Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-20005

Опубликовано: 13 сент. 2017
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

A flaw was found in nginx. When a date exists earlier than the standard epoch, as demonstrated by a file with a modification date in 1969 that causes a negative number to be treated as an unsigned integer, the year field becomes five characters long, larger than is allocated for, leading to a buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

This issue did not affect the versions of nginx as shipped with Red Hat Enterprise Linux 8 and Red Hat Software Collection 3 as they already have the patch applied.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2nginxNot affected
Red Hat Ansible Tower 3nginxNot affected
Red Hat Enterprise Linux 8nginx:1.16/nginxNot affected
Red Hat Enterprise Linux 8nginx:1.18/nginxNot affected
Red Hat Enterprise Linux 9nginxNot affected
Red Hat Software Collectionsrh-nginx116-nginxNot affected
Red Hat Software Collectionsrh-nginx118-nginxNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1974192nginx: buffer overflow in ngx_gmtime() triggered by 5 digit years

EPSS

Процентиль: 87%
0.03285
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

CVSS3: 9.8
nvd
около 5 лет назад

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

CVSS3: 9.8
debian
около 5 лет назад

NGINX before 1.13.6 has a buffer overflow for years that exceed four d ...

CVSS3: 9.8
github
около 4 лет назад

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

CVSS3: 9.8
fstec
почти 9 лет назад

Уязвимость модуля autoindex сервера NGINX, связанная с целочисленным переполнением, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 87%
0.03285
Низкий

9.8 Critical

CVSS3