CVE Database
/

CVE-2016-1247

Back to search

CVE-2016-1247

Published: Nov 29, 2016

Modified: Aug 5, 2024

PUBLISHED

Description

The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.

VendorProductVersions

n/a

n/a

affected
n/a

References

40768
exploit
x_refsource_EXPLOIT-DB
DSA-3701
vendor-advisory
x_refsource_DEBIAN
93903
vdb-entry
x_refsource_BID
USN-3114-1
vendor-advisory
x_refsource_UBUNTU
GLSA-201701-22
vendor-advisory
x_refsource_GENTOO
1037104
vdb-entry
x_refsource_SECTRACK
FEDORA-2021-10c1cd4cba
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-1556d440ba
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-3aa9ac7fd1
vendor-advisory
x_refsource_FEDORA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now