Privilege escalation - CVE-2016-1247

 

Privilege escalation - CVE-2016-1247

Published: October 26, 2016 / Updated: September 14, 2018


Vulnerability identifier: #VU1082
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1247
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to gain elevated privileges on the target system.
The weakness is due to improper handling of log file permissions in the '/var/log/nginx' directory by nginx packages. A locall attacker with 'www-data' user privileges can obtain root privileges on the target system.
Successful exploitation of the vulnerability results in privilege escalation on the vulnerable system.

Affected software

Arch Linux
Gentoo Linux
SUSE Linux Enterprise Micro
Fedora
Ubuntu
Junos OS
nginx
sssd-ldap
sssd-debugsource
libsss_idmap0
sssd-common
sssd-common-debuginfo
libsss_certmap0
libsss_nss_idmap0-debuginfo
sssd-ldap-debuginfo
sssd-krb5-common
sssd-krb5-common-debuginfo
libsss_nss_idmap0
libsss_certmap0-debuginfo
libsss_idmap0-debuginfo
sssd
PowerFlex rack

How to mitigate CVE-2016-1247

Update to version 1.6.2-5+deb8u3.

Junos OS - addressed in versions 21.4R3-S8, 22.2R3-S5, 22.3R3-S3, 22.4R3-S4, 23.2R2-S2, 23.4R2-S1, 24.2R1
nginx - addressed in versions 1.20.0-2.fc32, 1.20.0-2.fc33, 1.20.0-2.fc34, 1.20.1-1.el7, 1.20.1-2.el7
sssd-ldap - update to 2.5.2-150500.10.20.2
sssd-debugsource - update to 2.5.2-150500.10.20.2
libsss_idmap0 - update to 2.5.2-150500.10.20.2
sssd-common - update to 2.5.2-150500.10.20.2
sssd-common-debuginfo - update to 2.5.2-150500.10.20.2
libsss_certmap0 - update to 2.5.2-150500.10.20.2
libsss_nss_idmap0-debuginfo - update to 2.5.2-150500.10.20.2
sssd-ldap-debuginfo - update to 2.5.2-150500.10.20.2
sssd-krb5-common - update to 2.5.2-150500.10.20.2
sssd-krb5-common-debuginfo - update to 2.5.2-150500.10.20.2
libsss_nss_idmap0 - update to 2.5.2-150500.10.20.2
libsss_certmap0-debuginfo - update to 2.5.2-150500.10.20.2
libsss_idmap0-debuginfo - update to 2.5.2-150500.10.20.2
sssd - update to 2.5.2-150500.10.20.2
PowerFlex rack - update to 3.6.6.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins