Vulnerability Description
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Nginx | < 1.13.6 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- http://nginx.org/en/CHANGESRelease NotesVendor Advisory
- https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccfPatchThird Party Advisory
- https://github.com/nginx/nginx/commit/b900cc28fcbb4cf5a32ab62f80b59292e1c85b4bPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/06/msg00009.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0006/Third Party Advisory
- https://trac.nginx.org/nginx/ticket/1368ExploitPatchVendor Advisory
- http://nginx.org/en/CHANGESRelease NotesVendor Advisory
- https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccfPatchThird Party Advisory
- https://github.com/nginx/nginx/commit/b900cc28fcbb4cf5a32ab62f80b59292e1c85b4bPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/06/msg00009.htmlMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0006/Third Party Advisory
- https://trac.nginx.org/nginx/ticket/1368ExploitPatchVendor Advisory
FAQ
What is CVE-2017-20005?
CVE-2017-20005 is a vulnerability with a CVSS score of 9.8 (CRITICAL). NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date fa...
How severe is CVE-2017-20005?
CVE-2017-20005 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-20005?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Nginx, Debian Debian Linux.