Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-769v-gfhq-g2w7

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

EPSS

Процентиль: 95%
0.08433
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

redhat
больше 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

CVSS3: 5.3
nvd
больше 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

CVSS3: 5.3
debian
больше 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not pr ...

suse-cvrf
больше 10 лет назад

Security update for nginx

EPSS

Процентиль: 95%
0.08433
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400