CVE-2021-31807

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
squid-cachesquid
3.0 ≤
𝑥
< 4.15
squid-cachesquid
5.0 ≤
𝑥
< 5.0.6
squid-cachesquid
2.5.stable2:stable2
squid-cachesquid
2.5.stable3:stable3
squid-cachesquid
2.5.stable4:stable4
squid-cachesquid
2.5.stable5:stable5
squid-cachesquid
2.5.stable6:stable6
squid-cachesquid
2.5.stable7:stable7
squid-cachesquid
2.5.stable8:stable8
squid-cachesquid
2.5.stable9:stable9
squid-cachesquid
2.5.stable10:stable10
squid-cachesquid
2.5.stable11:stable11
squid-cachesquid
2.5.stable12:stable12
squid-cachesquid
2.5.stable13:stable13
squid-cachesquid
2.5.stable14:stable14
squid-cachesquid
2.6
squid-cachesquid
2.7
squid-cachesquid
2.7:stable2
squid-cachesquid
2.7:stable3
squid-cachesquid
2.7:stable4
squid-cachesquid
2.7:stable5
squid-cachesquid
2.7:stable6
squid-cachesquid
2.7:stable7
squid-cachesquid
2.7:stable8
squid-cachesquid
2.7:stable9
netappcloud_manager
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
squid
bullseye
4.13-10+deb11u3
fixed
bullseye (security)
4.13-10+deb11u3
fixed
bookworm
5.7-2+deb12u2
fixed
bookworm (security)
5.7-2+deb12u2
fixed
sid
6.12-1
fixed
trixie
6.12-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
squid
noble
Fixed 4.13-10ubuntu1
released
mantic
Fixed 4.13-10ubuntu1
released
lunar
Fixed 4.13-10ubuntu1
released
kinetic
Fixed 4.13-10ubuntu1
released
jammy
Fixed 4.13-10ubuntu1
released
impish
Fixed 4.13-10ubuntu1
released
hirsute
Fixed 4.13-1ubuntu4.1
released
groovy
Fixed 4.13-1ubuntu2.2
released
focal
Fixed 4.10-1ubuntu1.4
released
bionic
dne
xenial
dne
trusty
dne
squid3
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
dne
bionic
Fixed 3.5.27-1ubuntu1.11
released
xenial
needed
trusty
dne