← Back

CVE-2021-31807

nvd nist
Published: Jun 8, 2021Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.

Affected (28)

1 product
Squid
1 product
Fedora
1 product
Cloud Manager
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Squid Cache
From 3.0 to 4.15
From 5.0 to 5.0.6
Version 2.5.stable10
Version 2.5.stable11
Version 2.5.stable12
Version 2.5.stable13
Version 2.5.stable14
Version 2.5.stable2
Version 2.5.stable3
Version 2.5.stable4
Version 2.5.stable5
Version 2.5.stable6
Version 2.5.stable7
Version 2.5.stable8
Version 2.5.stable9
Version 2.6
Version 2.7
Version 2.7 stable2
Version 2.7 stable3
Version 2.7 stable4
Version 2.7 stable5
Version 2.7 stable6
Version 2.7 stable7
Version 2.7 stable8
Version 2.7 stable9
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (16)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.