Buffer Overflow Vulnerability in NGINX Affects Multiple Versions
CVE-2017-20005
9.8CRITICAL
What is CVE-2017-20005?
NGINX prior to version 1.13.6 is susceptible to a buffer overflow vulnerability caused by improper handling of years exceeding four digits in the autoindex module. This issue can be triggered by certain modification dates, such as those set to an invalid year or an integer overflow resulting from a far future date. This flaw can potentially lead to unpredictable behavior in NGINX and could be exploited by malicious users to disrupt service.