CVE-2021-31807

Updated: 2025-08-20 00:18:03.202484

Description:

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 4.0
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS squid34 3.4.14 6.5 MEDIUM Ignored 2021-11-02 14:03:20 Ignored due to low severity
CentOS 6 ELS squid 3.1.23 6.5 MEDIUM Ignored 2021-11-02 14:03:19 Ignored due to low severity
CentOS 8.4 ELS squid 4.11-4 6.5 MEDIUM Released CLSA-2022:1646060698 2022-02-28 14:41:40
CentOS 8.5 ELS squid 4.15-1 6.5 MEDIUM Not Vulnerable 2022-02-17 12:11:05
CloudLinux 6 ELS squid34 3.4.14 6.5 MEDIUM Ignored 2021-11-02 14:03:20 Ignored due to low severity
CloudLinux 6 ELS squid 3.1.23 6.5 MEDIUM Ignored 2021-11-02 14:03:19 Ignored due to low severity
CloudLinux 7 ELS squid 3.5.20 6.5 MEDIUM Released CLSA-2024:1733909428 2024-12-25 23:21:38
Debian 10 ELS squid 4.6.0 6.5 MEDIUM Ignored 2025-10-11 00:19:56 Ignored due to low severity
Oracle Linux 6 ELS squid 3.1.23 6.5 MEDIUM Ignored 2021-11-02 14:03:20 Ignored due to low severity
Oracle Linux 6 ELS squid34 3.4.14 6.5 MEDIUM Ignored 2021-11-02 14:03:20 Ignored due to low severity
Total: 13