nginx: buffer overflow in ngx_gmtime() triggered by 5 digit years
Published Jun 6, 2021
9.8
CRITICALCVSS 3.1
EPSS 3.26%
Description
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
Affected products
No data.
Configuration 2
- 9.0
No data.
Red Hat Ansible Automation Platform 1.2
nginx
Not affected
Red Hat Ansible Tower 3
nginx
Not affected
Red Hat Enterprise Linux 8
nginx:1.16/nginx
Not affected
Red Hat Enterprise Linux 8
nginx:1.18/nginx
Not affected
Red Hat Enterprise Linux 9
nginx
Not affected
Red Hat Software Collections
rh-nginx116-nginx
Not affected
Red Hat Software Collections
rh-nginx118-nginx
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 1.2 | nginx | Not affected | n/a |
| Red Hat Ansible Tower 3 | nginx | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nginx:1.16/nginx | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nginx:1.18/nginx | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nginx | Not affected | n/a |
| Red Hat Software Collections | rh-nginx116-nginx | Not affected | n/a |
| Red Hat Software Collections | rh-nginx118-nginx | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of nginx as shipped with Red Hat Enterprise Linux 8 and Red Hat Software Collection 3 as they already have the patch applied.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Dec 4, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.26% (0.03258) | 87.95th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.26% (0.03258) | 86.71th | v5 (v2026.06.15) |
| Oct 1, 2025 | 3.23% (0.03231) | 86.64th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.10% (0.02103) | 82.51th | v4 (v2025.03.14) |
| Mar 29, 2025 | 4.34% (0.04342) | 81.19th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.10% (0.02103) | 82.88th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.19% (0.01194) | 85.78th | v3 (v2023.03.01) |
| Jun 23, 2024 | 1.19% (0.01194) | 85.21th | v3 (v2023.03.01) |
| Feb 20, 2024 | 0.84% (0.00845) | 81.62th | v3 (v2023.03.01) |
| Jan 11, 2024 | 0.77% (0.00766) | 79.20th | v3 (v2023.03.01) |
| Aug 29, 2023 | 0.65% (0.00645) | 76.64th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.50% (0.00499) | 72.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.11% (0.01108) | 55.18th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.11% (0.01108) | 53.57th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.11% (0.01108) | 29.61th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.45% (0.01454) | 32.67th | v1 |
| Jan 6, 2022 | 1.45% (0.01454) | 31.96th | v1 |
| Sep 1, 2021 | 1.45% (0.01454) | 71.88th | v1 |
| Aug 6, 2021 | 1.45% (0.01454) | 0.00th | v1 |
| Jun 13, 2021 | 1.25% (0.01247) | 0.00th | v1 |
| Jun 8, 2021 | 5.36% (0.05363) | 0.00th | v1 |
References (10)
- http://nginx.org/en/CHANGES x_refsource_MISCRelease NotesVendor Advisory
- https://access.redhat.com/security/cve/CVE-2017-20005 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1974192 Issue Tracking
- https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccf x_refsource_MISCPatchThird Party Advisory
- https://github.com/nginx/nginx/commit/b900cc28fcbb4cf5a32ab62f80b59292e1c85b4b x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/06/msg00009.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-20005
- https://security.netapp.com/advisory/ntap-20210805-0006/ x_refsource_CONFIRMThird Party Advisory
- https://trac.nginx.org/nginx/ticket/1368 x_refsource_MISCExploitPatchVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-20005
| Link | Providers | Tags |
|---|---|---|
| http://nginx.org/en/CHANGES | x_refsource_MISCRelease NotesVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2017-20005 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1974192 | Issue Tracking | |
| https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccf | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/nginx/nginx/commit/b900cc28fcbb4cf5a32ab62f80b59292e1c85b4b | x_refsource_MISCPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2021/06/msg00009.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-20005 | ||
| https://security.netapp.com/advisory/ntap-20210805-0006/ | x_refsource_CONFIRMThird Party Advisory | |
| https://trac.nginx.org/nginx/ticket/1368 | x_refsource_MISCExploitPatchVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2017-20005 |
Change history (0)
No recorded changes yet.