Vulnerability Intelligence Report
CVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
No Active Exploit Signals
CVSS Base Score
7.8
HIGH
EPSS Probability:4.86%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| f5 | nginx | all |
| canonical | ubuntu_linux | 16.10, 16.04, 14.04 |
| debian | debian_linux | 8.0 |
| fedoraproject | fedora | 33, 34, 35 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
4.863%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Debian GNU/Linux · Vendor · USA |
| Reserved | 2015-12-27T00:00:00 |
| Published | 2016-11-29T17:00:00 |
| Patch Date | 2016-10-25 |
| Last Updated | 2024-08-05T22:48:13 |
Community Chatter & Buzz