[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-1247Date: (C)2016-12-01   (M)2023-12-22


The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.8CVSS Score : 7.2
Exploit Score: 1.8Exploit Score: 3.9
Impact Score: 5.9Impact Score: 10.0
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: COMPLETE
Scope: UNCHANGEDIntegrity: COMPLETE
Confidentiality: HIGHAvailability: COMPLETE
Integrity: HIGH 
Availability: HIGH 
  
Reference:
SECTRACK-1037104
http://seclists.org/fulldisclosure/2016/Nov/78
http://www.securityfocus.com/archive/1/539796/100/0/threaded
http://seclists.org/fulldisclosure/2017/Jan/33
EXPLOIT-DB-40768
BID-93903
DSA-3701
FEDORA-2021-10c1cd4cba
FEDORA-2021-1556d440ba
FEDORA-2021-3aa9ac7fd1
GLSA-201701-22
USN-3114-1
http://packetstormsecurity.com/files/139750/Nginx-Debian-Based-Distros-Root-Privilege-Escalation.html
https://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-PrivEsc-CVE-2016-1247.html
https://www.youtube.com/watch?v=aTswN1k1fQs

CPE    4
cpe:/o:debian:debian_linux:8.0
cpe:/o:canonical:ubuntu_linux:16.10
cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
cpe:/o:canonical:ubuntu_linux:14.04::~~lts~~~
...
CWE    1
CWE-59
OVAL    8
oval:org.secpod.oval:def:120083
oval:org.secpod.oval:def:120076
oval:org.secpod.oval:def:120086
oval:org.secpod.oval:def:602654
...

© SecPod Technologies