The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade nginx-all-modulesUpgrade nginx-filesystemUpgrade nginx-mod-mailUpgrade nginxUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-streamUpgrade nginx-mod-http-geoipUpgrade nginx-mod-http-image-filterUpgrade nginx-debuginfoUpgrade nginx-mod-http-perl | Sep 28, 2023 | Nov 29, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Nov 29, 2016 |
| Debian | — | Upgrade nginx | Oct 25, 2016 | Oct 25, 2016 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Oct 30, 2017 | Nov 29, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 25, 2016 |
| Ubuntu | — | Upgrade nginx-coreUpgrade nginx-lightUpgrade nginx-commonUpgrade nginx-fullUpgrade nginx-extras | Oct 25, 2016 | Oct 25, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub