Total vulnerabilities in the database
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
Software | From | Fixed in |
---|---|---|
f5 / nginx | 0.6.18 | 1.8.1 |
f5 / nginx | 1.9.0 | 1.9.10 |
canonical / ubuntu_linux | 15.10 | 15.10.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 7.0 | 7.0.x |
debian / debian_linux | 9.0 | 9.0.x |
opensuse / leap | 42.1 | 42.1.x |
apple / xcode | - | 13.0 |