Description
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
Remediation
References
Related Vulnerabilities
Drupal Core 6.x Cross-Site Scripting (6.0 - 6.10)
WordPress Plugin Qtranslate Slug Cross-Site Request Forgery (1.1.18)
WordPress Insecure Default Initialization of Resource Vulnerability (CVE-2017-5491)
WebLogic CVE-2020-2552 Vulnerability (CVE-2020-2552)
WordPress Plugin WordPress renaming tool by Vlajo Arbitrary File Download (1.0)