CVE-2021-31806: Input Validation
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing.
Other sources
Due to an incorrect input validation bug Squid is vulnerable to a Denial of Service attack against all clients using the proxy.
External Reference:
https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-31806?
CVE-2021-31806 is a vulnerability in Squid before 4.15 and 5.x before 5.0.6 that allows a Denial of Service attack via HTTP Range request processing.
How severe is CVE-2021-31806?
CVE-2021-31806 has a severity rating of 6.5 (high).
Which software versions are affected by CVE-2021-31806?
CVE-2021-31806 affects Squid versions before 4.15 and 5.x before 5.0.6.
How can I fix CVE-2021-31806?
To fix CVE-2021-31806, update Squid to version 4.15 or 5.0.6 or later.
Where can I find more information about CVE-2021-31806?
You can find more information about CVE-2021-31806 on the Debian security tracker website.