NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
"2026-04-11T04:38:17Z"
[
{
"id": "CVE-2017-20005-12765fb7",
"signature_version": "v1",
"digest": {
"function_hash": "293745260880302260283390811779397824234",
"length": 954.0
},
"source": "https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccf",
"deprecated": false,
"target": {
"function": "ngx_gmtime",
"file": "src/core/ngx_times.c"
},
"signature_type": "Function"
},
{
"id": "CVE-2017-20005-cdbd1329",
"signature_version": "v1",
"digest": {
"line_hashes": [
"283647955193824656164418729188562737248",
"189195171931257442418315937708627504419",
"167636579516610846178920746557246670594",
"326015414903035413461299330815021167909",
"53713957463048725167029389610515505399",
"43300747572034154487194778189189219315",
"14008719561519033426361797626160661323",
"199959541468589506083450323703511189662",
"26431161033443707096591012429462889355",
"102878010187977122764595214866563315881",
"121718354356566928725733153498047312059",
"92758879232259713116006360265233425168"
],
"threshold": 0.9
},
"source": "https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccf",
"deprecated": false,
"target": {
"file": "src/core/ngx_times.c"
},
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-20005.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
}
]