Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 16.xx: USN-3115-1 Severe OpenSSH Security Flaw Detected

ubuntu
Calendar Grey October 25, 2016
Scroller Ubuntu
Ensure your Ubuntu system is up-to-date to mitigate the nginx security flaw that may lead to unauthorized accessibility.
The system could be made to run programs as an administrator.

Summary

The system could be made to run programs as an administrator.

Software Description:

- nginx: small, powerful, scalable web/proxy server

Details:

Dawid Golunski discovered that the nginx package incorrectly handled log

file permissions. A remote attacker could possibly use this issue to obtain

root privileges.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
  nginx-common                    1.10.1-0ubuntu1.1
  nginx-core                      1.10.1-0ubuntu1.1
  nginx-extras                    1.10.1-0ubuntu1.1
  nginx-full                      1.10.1-0ubuntu1.1
  nginx-light                     1.10.1-0ubuntu1.1

Ubuntu 16.04 LTS:
  nginx-common                    1.10.0-0ubuntu0.16.04.3
  nginx-core                      1.10.0-0ubuntu0.16.04.3
  nginx-extras                    1.10.0-0ubuntu0.16.04.3
  nginx-full                      1.10.0-0ubuntu0.16.04.3
  nginx-light                     1.10.0-0ubuntu0.16.04.3

Ubuntu 14.04 LTS:
  nginx-common                    1.4.6-1ubuntu3.6
  nginx-core                      1.4.6-1ubuntu3.6
  nginx-extras                    1.4.6-1ubuntu3.6
  nginx-full                      1.4.6-1ubuntu3.6
  nginx-light                     1.4.6-1ubuntu3.6

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3114-1

CVE-2016-1247

Severity
critical
Lowest
Low
Medium
High
Critical

October 25, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.