6.5
CVSSv3

CVE-2021-31807

Published: 08/06/2021 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

An issue exists in Squid prior to 4.15 and 5.x prior to 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 2.5.stable6

squid-cache squid 2.6

squid-cache squid 2.5.stable9

squid-cache squid 2.7

squid-cache squid 2.5.stable4

squid-cache squid 2.5.stable7

squid-cache squid 2.5.stable14

squid-cache squid 2.5.stable2

squid-cache squid 2.5.stable5

squid-cache squid 2.5.stable12

squid-cache squid 2.5.stable13

squid-cache squid 2.5.stable11

squid-cache squid 2.5.stable3

squid-cache squid 2.5.stable8

squid-cache squid 2.5.stable10

squid-cache squid

fedoraproject fedora 33

fedoraproject fedora 34

netapp cloud manager -

Vendor Advisories

Debian Bug report logs - #989043 squid: CVE-2021-31806 CVE-2021-31807 CVE-2021-31808 Package: src:squid; Maintainer for src:squid is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 24 May 2021 15:30:01 UTC Severity: important Tags: security, upstream Found in vers ...
Multiple denial of service vulnerabilities were discovered in the Squid proxy caching server For the stable distribution (buster), these problems have been fixed in version 46-1+deb10u6 We recommend that you upgrade your squid packages For the detailed security status of squid please refer to its security tracker page at: security-track ...
An issue was discovered in Squid before 415 and 5x before 506 Due to a buffer-management bug, it allows a denial of service When resolving a request with the urn: scheme, the parser leaks a small amount of memory However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption (CVE-2021-28651) ...
An issue was discovered in Squid before 415 and 5x before 506 Due to a buffer-management bug, it allows a denial of service When resolving a request with the urn: scheme, the parser leaks a small amount of memory However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption (CVE-2021-28651) ...
Squid through 414 and 5x through 505, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data This can be leveraged as part of a chain for remote code execution as nobody (CVE-2021-28116) An issue was discovered in Squid before 415 and 5x before 506 Due to a buffer-management bug, it a ...
No description is available for this CVE ...
Due to an incorrect input validation bug Squid before version 415 is vulnerable to a denial of service attack against all clients using the proxy by a trusted client making HTTP Range requests ...