NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
{
"unresolved_ranges": [
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"vendor_product": "debian:debian_linux",
"extracted_events": [
{
"introduced": "9.0"
},
{
"last_affected": "9.0"
}
]
}
]
}{
"cpe": "cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.13.6"
}
]
}[
{
"digest": {
"length": 954.0,
"function_hash": "293745260880302260283390811779397824234"
},
"signature_version": "v1",
"source": "https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccf",
"signature_type": "Function",
"target": {
"function": "ngx_gmtime",
"file": "src/core/ngx_times.c"
},
"id": "CVE-2017-20005-12765fb7",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"37588762136811330033074117254741645493",
"111209216128424196797059434246210239092",
"98693140202448203048304883280104112253"
]
},
"signature_version": "v1",
"source": "https://github.com/nginx/nginx/commit/b900cc28fcbb4cf5a32ab62f80b59292e1c85b4b",
"signature_type": "Line",
"target": {
"file": "src/core/ngx_times.c"
},
"id": "CVE-2017-20005-1325f535",
"deprecated": false
},
{
"digest": {
"length": 961.0,
"function_hash": "317045738056605005010604687115756241645"
},
"signature_version": "v1",
"source": "https://github.com/nginx/nginx/commit/b900cc28fcbb4cf5a32ab62f80b59292e1c85b4b",
"signature_type": "Function",
"target": {
"function": "ngx_gmtime",
"file": "src/core/ngx_times.c"
},
"id": "CVE-2017-20005-b8597391",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"283647955193824656164418729188562737248",
"189195171931257442418315937708627504419",
"167636579516610846178920746557246670594",
"326015414903035413461299330815021167909",
"53713957463048725167029389610515505399",
"43300747572034154487194778189189219315",
"14008719561519033426361797626160661323",
"199959541468589506083450323703511189662",
"26431161033443707096591012429462889355",
"102878010187977122764595214866563315881",
"121718354356566928725733153498047312059",
"92758879232259713116006360265233425168"
]
},
"signature_version": "v1",
"source": "https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccf",
"signature_type": "Line",
"target": {
"file": "src/core/ngx_times.c"
},
"id": "CVE-2017-20005-cdbd1329",
"deprecated": false
}
]
"2026-07-08T11:48:11Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-20005.json"