First published: Tue Jun 08 2021(Updated: )
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Squid-Cache Squid | >=3.0<4.15 | |
Squid-Cache Squid | >=5.0<5.0.6 | |
Squid-Cache Squid | =2.5.stable2 | |
Squid-Cache Squid | =2.5.stable3 | |
Squid-Cache Squid | =2.5.stable4 | |
Squid-Cache Squid | =2.5.stable5 | |
Squid-Cache Squid | =2.5.stable6 | |
Squid-Cache Squid | =2.5.stable7 | |
Squid-Cache Squid | =2.5.stable8 | |
Squid-Cache Squid | =2.5.stable9 | |
Squid-Cache Squid | =2.5.stable10 | |
Squid-Cache Squid | =2.5.stable11 | |
Squid-Cache Squid | =2.5.stable12 | |
Squid-Cache Squid | =2.5.stable13 | |
Squid-Cache Squid | =2.5.stable14 | |
Squid-Cache Squid | =2.6 | |
Squid-Cache Squid | =2.7 | |
Squid-Cache Squid | =2.7-stable2 | |
Squid-Cache Squid | =2.7-stable3 | |
Squid-Cache Squid | =2.7-stable4 | |
Squid-Cache Squid | =2.7-stable5 | |
Squid-Cache Squid | =2.7-stable6 | |
Squid-Cache Squid | =2.7-stable7 | |
Squid-Cache Squid | =2.7-stable8 | |
Squid-Cache Squid | =2.7-stable9 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
NetApp Cloud Manager | ||
debian/squid | 4.13-10+deb11u3 5.7-2+deb12u2 6.12-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31807 is a vulnerability discovered in Squid before 4.15 and 5.x before 5.0.6 that allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests.
CVE-2021-31807 affects Squid versions before 4.15 and 5.x before 5.0.6, potentially leading to denial of service.
The severity of CVE-2021-31807 is medium, with a CVSS score of 6.5.
To fix CVE-2021-31807, upgrade to Squid version 4.15 or 5.0.6 or later.
You can find more information about CVE-2021-31807 at the following references: [reference1](http://seclists.org/fulldisclosure/2023/Oct/14), [reference2](http://www.openwall.com/lists/oss-security/2023/10/11/3), [reference3](http://www.squid-cache.org/Versions/v4/changesets/squid-4-e7cf864f938f24eea8af0692c04d16790983c823.patch)