Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-20005

Опубликовано: 13 сент. 2017
Источник: redhat
CVSS3: 9.8

Описание

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

A flaw was found in nginx. When a date exists earlier than the standard epoch, as demonstrated by a file with a modification date in 1969 that causes a negative number to be treated as an unsigned integer, the year field becomes five characters long, larger than is allocated for, leading to a buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

This issue did not affect the versions of nginx as shipped with Red Hat Enterprise Linux 8 and Red Hat Software Collection 3 as they already have the patch applied.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 1.2nginxNot affected
Red Hat Ansible Tower 3nginxNot affected
Red Hat Enterprise Linux 8nginx:1.16/nginxNot affected
Red Hat Enterprise Linux 8nginx:1.18/nginxNot affected
Red Hat Enterprise Linux 9nginxNot affected
Red Hat Software Collectionsrh-nginx116-nginxNot affected
Red Hat Software Collectionsrh-nginx118-nginxNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1974192nginx: buffer overflow in ngx_gmtime() triggered by 5 digit years

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

CVSS3: 9.8
nvd
больше 4 лет назад

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

CVSS3: 9.8
debian
больше 4 лет назад

NGINX before 1.13.6 has a buffer overflow for years that exceed four d ...

CVSS3: 9.8
github
больше 3 лет назад

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

CVSS3: 9.8
fstec
больше 8 лет назад

Уязвимость модуля autoindex сервера NGINX, связанная с целочисленным переполнением, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

9.8 Critical

CVSS3