A buffer overflow was found in within the NTLM authentication helper routine. If Squid is configured to use the NTLM authentication helper, a remote attacker could potentially execute arbitrary code by sending an overly long password. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0541 to this issue. Note: The NTLM authentication helper is not enabled by default in Fedora Core. Note; This is a stack buffer overflow and exec-shield will help mitigate the risk of this being exploited in Fedora Core.
http://www.redhat.com/archives/fedora-announce-list/2004-June/msg00012.html http://www.redhat.com/archives/fedora-announce-list/2004-June/msg00013.html