PublicDateAtUSN: 2016-10-25 Candidate: CVE-2016-1247 PublicDate: 2016-11-29 17:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1247 https://ubuntu.com/security/notices/USN-3114-1 http://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-PrivEsc-CVE-2016-1247.html Description: The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log. Ubuntu-Description: Notes: mdeslaur> Ubuntu 12.04 LTS never got the update for CVE-2013-0337 which mdeslaur> introduced this issue. Bugs: Priority: medium Discovered-by: Dawid Golunski Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_nginx: upstream_nginx: needs-triage precise_nginx: not-affected (1.1.19-1ubuntu0.8) trusty_nginx: released (1.4.6-1ubuntu3.6) trusty/esm_nginx: released (1.4.6-1ubuntu3.6) vivid/stable-phone-overlay_nginx: DNE vivid/ubuntu-core_nginx: DNE xenial_nginx: released (1.10.0-0ubuntu0.16.04.3) esm-infra/xenial_nginx: released (1.10.0-0ubuntu0.16.04.3) yakkety_nginx: released (1.10.1-0ubuntu1.1) devel_nginx: released (1.10.1-0ubuntu5)