CVE Vulnerabilities

CVE-2013-0337

Published: Oct 27, 2013 | Modified: Nov 10, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.

Affected Software

Name Vendor Start Version End Version
Nginx F5 * 1.3.13 (including)
Nginx F5 1.0.0 (including) 1.0.0 (including)
Nginx F5 1.0.1 (including) 1.0.1 (including)
Nginx F5 1.0.2 (including) 1.0.2 (including)
Nginx F5 1.0.3 (including) 1.0.3 (including)
Nginx F5 1.0.4 (including) 1.0.4 (including)
Nginx F5 1.0.5 (including) 1.0.5 (including)
Nginx F5 1.0.6 (including) 1.0.6 (including)
Nginx F5 1.0.7 (including) 1.0.7 (including)
Nginx F5 1.0.8 (including) 1.0.8 (including)
Nginx F5 1.0.9 (including) 1.0.9 (including)
Nginx F5 1.0.10 (including) 1.0.10 (including)
Nginx F5 1.0.11 (including) 1.0.11 (including)
Nginx F5 1.0.12 (including) 1.0.12 (including)
Nginx F5 1.0.13 (including) 1.0.13 (including)
Nginx F5 1.0.14 (including) 1.0.14 (including)
Nginx F5 1.0.15 (including) 1.0.15 (including)
Nginx F5 1.1.0 (including) 1.1.0 (including)
Nginx F5 1.1.1 (including) 1.1.1 (including)
Nginx F5 1.1.2 (including) 1.1.2 (including)
Nginx F5 1.1.3 (including) 1.1.3 (including)
Nginx F5 1.1.4 (including) 1.1.4 (including)
Nginx F5 1.1.5 (including) 1.1.5 (including)
Nginx F5 1.1.6 (including) 1.1.6 (including)
Nginx F5 1.1.7 (including) 1.1.7 (including)
Nginx F5 1.1.8 (including) 1.1.8 (including)
Nginx F5 1.1.9 (including) 1.1.9 (including)
Nginx F5 1.1.10 (including) 1.1.10 (including)
Nginx F5 1.1.11 (including) 1.1.11 (including)
Nginx F5 1.1.12 (including) 1.1.12 (including)
Nginx F5 1.1.13 (including) 1.1.13 (including)
Nginx F5 1.1.14 (including) 1.1.14 (including)
Nginx F5 1.1.15 (including) 1.1.15 (including)
Nginx F5 1.1.16 (including) 1.1.16 (including)
Nginx F5 1.1.17 (including) 1.1.17 (including)
Nginx F5 1.1.18 (including) 1.1.18 (including)
Nginx F5 1.1.19 (including) 1.1.19 (including)
Nginx F5 1.2.0 (including) 1.2.0 (including)
Nginx F5 1.3.0 (including) 1.3.0 (including)
Nginx F5 1.3.1 (including) 1.3.1 (including)
Nginx F5 1.3.2 (including) 1.3.2 (including)
Nginx F5 1.3.3 (including) 1.3.3 (including)
Nginx F5 1.3.4 (including) 1.3.4 (including)
Nginx F5 1.3.5 (including) 1.3.5 (including)
Nginx F5 1.3.6 (including) 1.3.6 (including)
Nginx F5 1.3.7 (including) 1.3.7 (including)
Nginx F5 1.3.8 (including) 1.3.8 (including)
Nginx F5 1.3.9 (including) 1.3.9 (including)
Nginx F5 1.3.10 (including) 1.3.10 (including)
Nginx F5 1.3.11 (including) 1.3.11 (including)
Nginx F5 1.3.12 (including) 1.3.12 (including)
Nginx Ubuntu artful *
Nginx Ubuntu bionic *
Nginx Ubuntu devel *
Nginx Ubuntu esm-infra-legacy/trusty *
Nginx Ubuntu esm-infra/bionic *
Nginx Ubuntu esm-infra/xenial *
Nginx Ubuntu hardy *
Nginx Ubuntu lucid *
Nginx Ubuntu oneiric *
Nginx Ubuntu precise *
Nginx Ubuntu quantal *
Nginx Ubuntu raring *
Nginx Ubuntu saucy *
Nginx Ubuntu trusty *
Nginx Ubuntu trusty/esm *
Nginx Ubuntu upstream *
Nginx Ubuntu xenial *
Nginx Ubuntu yakkety *
Nginx Ubuntu zesty *

References