The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-nginxamazon-linux-ami-2-upgrade-nginx-all-modulesamazon-linux-ami-2-upgrade-nginx-debuginfoamazon-linux-ami-2-upgrade-nginx-filesystemamazon-linux-ami-2-upgrade-nginx-mod-http-geoipamazon-linux-ami-2-upgrade-nginx-mod-http-image-filteramazon-linux-ami-2-upgrade-nginx-mod-http-perlamazon-linux-ami-2-upgrade-nginx-mod-http-xslt-filteramazon-linux-ami-2-upgrade-nginx-mod-mailamazon-linux-ami-2-upgrade-nginx-mod-stream | Sep 28, 2023 | Nov 29, 2016 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Nov 29, 2016 | |
| Debian | debian-upgrade-nginx | Oct 25, 2016 | Oct 25, 2016 | |
| Gentoo Linux | gentoo-linux-upgrade-www-servers-nginx | Oct 30, 2017 | Nov 29, 2016 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Oct 25, 2016 |
| Ubuntu | ubuntu-upgrade-nginx-commonubuntu-upgrade-nginx-coreubuntu-upgrade-nginx-extrasubuntu-upgrade-nginx-fullubuntu-upgrade-nginx-light | Oct 25, 2016 | Oct 25, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub