Back

CRITICAL

nginx: buffer overflow in ngx_gmtime() triggered by 5 digit years

Published Jun 6, 2021

Description

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of nginx as shipped with Red Hat Enterprise Linux 8 and Red Hat Software Collection 3 as they already have the patch applied.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 6, 2021
Updated Dec 5, 2025
Reserved Jun 6, 2021
CISA Vulnrichment
Updated Dec 4, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 13, 2017