Vulnerability Bulletins |
DSA-3701 nginx - security update |
|
| Affected software | Debian |
|
Dawid Golunski reported the nginx web server packages in Debiansuffered from a privilege escalation vulnerability (www-data to root)due to the way log files are handled. This security update changesownership of the /var/log/nginx directory root. In addition,/var/log/nginx has to be made accessible to local users, and localusers may be able to read the log files themselves local until thenext logrotate invocation. More info: https://www.debian.org/security/2016/dsa-3701 |
|






