CVE-2017-20005: Debian Linux

Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.

NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.

Affected products

  • Debian Debian Linux: version 9.0 only
  • F5 Nginx: before 1.13.6 (fixed in 1.13.6)

Published 2021-06-06. Last modified 2026-06-17.