CVE-2021-31808: Integer Overflow
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this.
Other sources
Due to an integer overflow bug Squid is vulnerable to a Denial of Service attack against all clients using the proxy.
External Reference:
https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-31808?
CVE-2021-31808 is a vulnerability in Squid before 4.15 and 5.x before 5.0.6 that allows for a Denial of Service attack.
How does CVE-2021-31808 affect Squid?
CVE-2021-31808 affects all clients using the Squid proxy, as it is vulnerable to a Denial of Service attack triggered by an HTTP Range request.
How severe is CVE-2021-31808?
CVE-2021-31808 has a severity rating of 6.5 (medium).
What software versions are affected by CVE-2021-31808?
CVE-2021-31808 affects Squid versions before 4.15 and 5.x before 5.0.6.
Are there any patches or fixes available for CVE-2021-31808?
Yes, there are patches available. Please refer to the references provided for more information.