Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-31807

Опубликовано: 08 июн. 2021
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Средний

Описание

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*
Версия от 3.0 (включая) до 4.15 (исключая)
cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*
Версия от 5.0 (включая) до 5.0.6 (исключая)
cpe:2.3:a:squid-cache:squid:2.5.stable2:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable5:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable6:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable7:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable8:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable9:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable10:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable11:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable12:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable13:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.5.stable14:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.6:*:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:-:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable2:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable3:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable4:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable5:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable6:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable7:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable8:*:*:*:*:*:*
cpe:2.3:a:squid-cache:squid:2.7:stable9:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.3759
Средний

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.

CVSS3: 6.5
redhat
около 4 лет назад

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.

CVSS3: 6.5
debian
около 4 лет назад

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An ...

CVSS3: 6.5
github
около 3 лет назад

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.

CVSS3: 6.5
fstec
около 4 лет назад

Уязвимость прокси-сервера Squid, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 97%
0.3759
Средний

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-190