Vulnerability Bulletins

DSA-3701 nginx - security update

   
Affected software Debian
 
Dawid Golunski reported the nginx web server packages in Debiansuffered from a privilege escalation vulnerability (www-data to root)due to the way log files are handled. This security update changesownership of the /var/log/nginx directory root. In addition,/var/log/nginx has to be made accessible to local users, and localusers may be able to read the log files themselves local until thenext logrotate invocation.

More info:

https://www.debian.org/security/2016/dsa-3701