CVE-2021-31806

Updated: 2025-08-20 00:03:23.716786

Description:

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 4.0
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS squid34 3.4.14 6.5 MEDIUM Ignored 2021-11-02 14:03:20 Ignored due to low severity
CentOS 6 ELS squid 3.1.23 6.5 MEDIUM Ignored 2021-11-02 14:03:20 Ignored due to low severity
CentOS 8.4 ELS squid 4.11-4 6.5 MEDIUM Released CLSA-2022:1646060698 2022-02-28 14:41:40
CentOS 8.5 ELS squid 4.15-1 6.5 MEDIUM Not Vulnerable 2022-02-17 12:11:05
CloudLinux 6 ELS squid34 3.4.14 6.5 MEDIUM Ignored 2021-11-02 14:03:20 We have reasoned not to port the fix for this vulnerability due to low base score of the CVE
CloudLinux 6 ELS squid 3.1.23 6.5 MEDIUM Ignored 2021-11-02 14:03:20 We have reasoned not to port the fix for this vulnerability due to low base score of the CVE
CloudLinux 7 ELS squid 3.5.20 6.5 MEDIUM Released CLSA-2024:1733909428 2024-12-25 23:21:38
Debian 10 ELS squid 4.6.0 6.5 MEDIUM Ignored 2025-10-11 00:19:31 Ignored due to low severity
Oracle Linux 6 ELS squid 3.1.23 6.5 MEDIUM Ignored 2021-11-02 14:03:20 Ignored due to low severity
Oracle Linux 6 ELS squid34 3.4.14 6.5 MEDIUM Ignored 2021-11-02 14:03:20 Ignored due to low severity
Total: 13