4 ms·
nginx-common (1.6.2-5+deb8u3) jessie-security; urgency=high In order to secure nginx against privilege escalation attacks, we are changing the way log file
by marksamman 10y ago
nginx-common (1.6.2-5+deb8u3) jessie-security; urgency=high
In order to secure nginx against privilege escalation attacks, we are
changing the way log file owners & permissions are handled so that www-data
is not allowed to symlink a logfile. /var/log/nginx is now owned by root:adm
and its permissions are changed to 0755. The package checks for such symlinks
on existing installations and informs the admin using debconf.
That unfortunately may come at a cost in terms of privacy. /var/log/nginx is
now world-readable, and nginx hardcodes permissions of non-existing logs to
0644. On systems running logrotate log files are private after the first
logrotate run, since the new log files are created with 0640 permissions.
-- Christos Trochalakis <yatiohi@ideopolis.gr> Tue, 04 Oct 2016 15:20:33 +0300
- 3pt14159 10y agoYikes this is pretty bad. Many log files (wrongly) include things like form fields including passwords and auth tokens.
- 0x0 10y agoIf you have www-data access you can probably grab those from memory. This vulnerability is about escalating to root. But if all your juicy data is already available to / passing through your nginx, then this patch isn't doing much to improve your situation.
- therein 10y agoExcept one requires the attacker to read from the processes memory in an organized way for an extended amount of time to snoop data while the other just puts its conveniently onto your disk.