CVE-2021-31806
MEDIUMSquid < 4.15 and 5.x < 5.0.6 - Denial of Service via HTTP Range Request Processing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-31806.
PoCs published by Joshua Rogers, including Metasploit module auxiliary/dos/http/squid_range_dos.
AI-analyzed exploit summary This Metasploit module exploits CVE-2021-31807 (and CVE-2021-31806) to trigger a denial-of-service in Squid Proxy by sending malformed HTTP Range headers. The exploit sends multiple crafted requests to crash the service.
Description
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing.
Exploits (1)
This Metasploit module exploits CVE-2021-31807 (and CVE-2021-31806) to trigger a denial-of-service in Squid Proxy by sending malformed HTTP Range headers. The exploit sends multiple crafted requests to crash the service.
References (9)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H