CVE-2021-31806
40Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendepss 96%
de la publicación al arma0 días
Publicada en NVD27 may
metasploit27 may
probabilidad de explotación
96%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Lo que declaran los fabricantes (VEX)
Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.
Red Hatdocumento VEX ↗
Afectado
2 productos (8 componentes)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7
workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Corregido
No afectado
1 producto (2 componentes) — porque el código vulnerable no está presente en el producto
Red Hat Enterprise Linux 9
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing.
Productos afectados
n/a · n/aReferencias
http://seclists.org/fulldisclosure/2023/Oct/14https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xfhttps://lists.debian.org/debian-lts-announce/2021/06/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSQ3U54ZCNXR44QRPW3AV2VCS6K3TKCF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4EPIWUZDJAXADDHVOPKRBTQHPBR6H66/https://security.netapp.com/advisory/ntap-20210716-0007/https://www.debian.org/security/2021/dsa-4924http://www.openwall.com/lists/oss-security/2023/10/11/3http://www.squid-cache.org/Versions/v4/changesets/squid-4-e7cf864f938f24eea8af0692c04d16790983c823.patch