Vulnerability Description
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Nginx | <= 1.10.1 |
| Canonical | Ubuntu Linux | 16.10 |
| Debian | Debian Linux | 8.0 |
| Fedoraproject | Fedora | 33 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/139750/Nginx-Debian-Based-Distros-Root-PrivExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2016/Nov/78Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2017/Jan/33Mailing ListThird Party Advisory
- http://www.debian.org/security/2016/dsa-3701Vendor Advisory
- http://www.securityfocus.com/archive/1/539796/100/0/threadedThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/93903Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037104Third Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-3114-1Vendor Advisory
- https://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-PrivEsc-CVE-2016-1247ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/201701-22Third Party Advisory
- https://www.exploit-db.com/exploits/40768/ExploitThird Party AdvisoryVDB Entry
- https://www.youtube.com/watch?v=aTswN1k1fQsExploitThird Party Advisory
FAQ
What is CVE-2016-1247?
CVE-2016-1247 is a vulnerability with a CVSS score of 7.8 (HIGH). The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1...
How severe is CVE-2016-1247?
CVE-2016-1247 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1247?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Nginx, Canonical Ubuntu Linux, Debian Debian Linux, Fedoraproject Fedora.