CVE-2016-1247

Description

The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
8.594

Associated Vulnerability

VulnerabilityOS Platform
Update Nginx to 9.1.19Windows
Update Nginx to 9.1.5Windows
Update Nginx to 9.1.8Windows
Update Nginx to 9.2.14Windows
Update Nginx to 9.2.19Windows
Update Nginx to 9.2.3Windows
Update Nginx to 9.2.7Windows
Update Nginx to 9.3.10Windows
Update Nginx to 9.3.15Windows
Update Nginx to 9.3.17Windows
small, powerful, scalable web/proxy server (USN-3114-1) nginx-core_1.4.6-1ubuntu3.6_i386.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-core_1.4.6-1ubuntu3.6_amd64.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-core_1.10.0-0ubuntu0.16.04.3_i386.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-core_1.10.0-0ubuntu0.16.04.3_amd64.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-full_1.4.6-1ubuntu3.6_i386.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-full_1.4.6-1ubuntu3.6_amd64.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-full_1.10.0-0ubuntu0.16.04.3_i386.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-full_1.10.0-0ubuntu0.16.04.3_amd64.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-light_1.4.6-1ubuntu3.6_i386.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-light_1.4.6-1ubuntu3.6_amd64.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-light_1.10.0-0ubuntu0.16.04.3_i386.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-light_1.10.0-0ubuntu0.16.04.3_amd64.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-common_1.4.6-1ubuntu3.6_all.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-common_1.10.0-0ubuntu0.16.04.3_all.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-extras_1.4.6-1ubuntu3.6_i386.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-extras_1.4.6-1ubuntu3.6_amd64.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-extras_1.10.0-0ubuntu0.16.04.3_i386.debLinux
small, powerful, scalable web/proxy server (USN-3114-1) nginx-extras_1.10.0-0ubuntu0.16.04.3_amd64.debLinux
nginx security update(DSA-3701-1) nginx_1.6.2-5+deb8u3_all.debLinux
Update Nginx to 9.1.19 (For Linux)Linux
Update Nginx to 9.1.5 (For Linux)Linux
Update Nginx to 9.1.8 (For Linux)Linux
Update Nginx to 9.2.14 (For Linux)Linux
Update Nginx to 9.2.19 (For Linux)Linux
Update Nginx to 9.2.3 (For Linux)Linux
Update Nginx to 9.2.7 (For Linux)Linux
Update Nginx to 9.3.10 (For Linux)Linux
Update Nginx to 9.3.15 (For Linux)Linux
Update Nginx to 9.3.17 (For Linux)Linux
Improper Link Resolution Before File Access (Link Following) Vulnerability (CVE-2016-1247)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234