The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade nginx-mod-http-perlUpgrade nginx-mod-streamUpgrade nginx-mod-http-image-filterUpgrade nginx-mod-http-geoipUpgrade nginx-debuginfoUpgrade nginx-mod-http-xslt-filterUpgrade nginxUpgrade nginx-all-modulesUpgrade nginx-mod-mailUpgrade nginx-filesystem | Sep 28, 2023 | Nov 29, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Nov 29, 2016 |
| Debian | — | Upgrade nginx | Oct 25, 2016 | Oct 25, 2016 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Oct 30, 2017 | Nov 29, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 25, 2016 |
| Ubuntu | — | Upgrade nginx-fullUpgrade nginx-extrasUpgrade nginx-commonUpgrade nginx-lightUpgrade nginx-core | Oct 25, 2016 | Oct 25, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub