« Volver al listado

CVE-2021-31807

Estado: ModificadaMedia (6.5)—

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-31807",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-06-08T20:15:09.057",
  "references": [
    {
      "url": "http://seclists.org/fulldisclosure/2023/Oct/14",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/10/11/3",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.squid-cache.org/Versions/v4/changesets/squid-4-e7cf864f938f24eea8af0692c04d16790983c823.patch",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00014.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSQ3U54ZCNXR44QRPW3AV2VCS6K3TKCF/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4EPIWUZDJAXADDHVOPKRBTQHPBR6H66/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20210716-0007/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2023/Oct/14",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/10/11/3",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.squid-cache.org/Versions/v4/changesets/squid-4-e7cf864f938f24eea8af0692c04d16790983c823.patch",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2021/06/msg00014.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSQ3U54ZCNXR44QRPW3AV2VCS6K3TKCF/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4EPIWUZDJAXADDHVOPKRBTQHPBR6H66/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20210716-0007/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent."
    },
    {
      "lang": "es",
      "value": "Se ha detectado un problema en Squid versiones anteriores a 4.15 y en versiones 5.x anteriores a 5.0.6. Un problema de desbordamiento de enteros permite a un servidor remoto conseguir una Denegación de Servicio cuando se entrega respuestas a peticiones de rango HTTP. El desencadenante del problema es un encabezado que puede esperarse que se presente en el tráfico HTTP sin ninguna intención maliciosa"
    }
  ],
  "lastModified": "2026-06-17T03:52:16.200",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9ED22D0-23B0-4441-91C9-CBC1C57A7D6D",
              "versionEndExcluding": "4.15",
              "versionStartIncluding": "3.0"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68801A75-0B13-444A-B88F-8BDD4EE953D3",
              "versionEndExcluding": "5.0.6",
              "versionStartIncluding": "5.0"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3DBDF00F-0FCC-4C6B-8541-7FBF2FF79CEB"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1460A9BC-464D-47FC-9CDE-08E094E84520"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA370C48-58E9-4A66-8CEB-01ABB90DDDF4"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7D47FF1-44FC-4798-B7DB-45B3825496AF"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6AFABF40-3269-44D6-98BE-30030002BB40"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15D4C357-F4AC-4BB3-889D-0B76DB28D8A0"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B16B99BF-4DC3-4525-8153-B45287DB5BA1"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00A8E046-A375-442D-B96B-DBD2993652AD"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE90AB17-3998-42D6-BB43-577C05BD8380"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B516FB5-5779-4F81-812B-A321E3E711FE"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DD5E8F7-19C7-4733-9A57-033572E8A78B"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB55AD78-C3FA-4DC5-81F0-83CB1385AE5E"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.5.stable14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B43CE92-434B-4F93-9355-F9CD6D5959EF"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AE100C3-0245-4305-B514-77D0572C2947"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.7:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4E50120-7298-4BC5-AC36-708EFCCFA1F8"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.7:stable2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFBB466C-C679-4B4B-87C2-E7853E5B3F04"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.7:stable3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A03692DD-779F-4E3C-861C-29943870A816"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.7:stable4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79FF6B3C-A3CE-4AA2-80F9-44D05A6B2F08"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.7:stable5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CF6E367-D33B-4B60-8C40-4618C47D53E8"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.7:stable6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0FA1F4FE-629C-4489-A13C-017A824C840F"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.7:stable7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2479C5BF-94E1-4153-9FA3-333BC00F01D6"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.7:stable8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8ABFCCCC-7584-466E-97CC-6EBD3934A70E"
            },
            {
              "criteria": "cpe:2.3:a:squid-cache:squid:2.7:stable9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F17E49BF-FB11-4EE6-B6AC-30914F381B2F"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E460AA51-FCDA-46B9-AE97-E6676AA5E194"
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A930E247-0B43-43CB-98FF-6CE7B8189835"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:cloud_manager:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "197D0D80-6702-4B61-B681-AFDBA7D69067"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}