7.8
CWE
59
Advisory Published
Updated

CVE-2016-1247

First published: Tue Nov 29 2016(Updated: )

The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.

Credit: security@debian.org

Affected SoftwareAffected VersionHow to fix
F5 NGINX App Protect<=1.10.1
Ubuntu=16.10
F5 NGINX App Protect<=1.10.0
Ubuntu=16.04
F5 NGINX App Protect<=1.6.2
Debian=8.0
F5 NGINX App Protect<=1.4.3
Ubuntu=14.04
Fedora=33
Fedora=34
Fedora=35

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2016-1247?

    CVE-2016-1247 is classified as a critical vulnerability that allows local users to escalate privileges.

  • How do I fix CVE-2016-1247?

    To fix CVE-2016-1247, upgrade the nginx package to the latest version available for your operating system that is not affected.

  • Which versions of nginx are affected by CVE-2016-1247?

    CVE-2016-1247 affects nginx versions before 1.6.2-5+deb8u3 on Debian and variations on Ubuntu up to version 1.10.1.

  • Can CVE-2016-1247 be exploited remotely?

    CVE-2016-1247 is not a remote vulnerability; it requires local user access to exploit.

  • What systems are impacted by CVE-2016-1247?

    CVE-2016-1247 affects Debian Jessie, Ubuntu 14.04 LTS, and Ubuntu 16.04 LTS among others.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203