The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
2016-11-29T17:59:00.167
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | f5 | nginx | ≤ 1.10.1 | Yes |
Operating System | canonical | ubuntu_linux | 16.10 | No |
Application | f5 | nginx | ≤ 1.10.0 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | No |
Application | f5 | nginx | ≤ 1.6.2 | Yes |
Operating System | debian | debian_linux | 8.0 | No |
Application | f5 | nginx | ≤ 1.4.3 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | No |
Operating System | fedoraproject | fedora | 33 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |