Description
When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery-Responsive Photo and Video Gallery by Limb Cross-Site Scripting (1.3.2)
Zope Web Application Server CVE-2011-2528 Vulnerability (CVE-2011-2528)
WordPress Plugin Easy Justified Gallery Cross-Site Scripting (1.0.8)
WordPress Plugin Stock in & out Cross-Site Scripting (1.0.4)
WordPress Plugin iThemes Security (formerly Better WP Security) Security Bypass (7.9.0)