CVE-2012-3380

Publication date 31 August 2012

Last updated 24 July 2024


Ubuntu priority

Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.

Read the notes from the security team

Status

Package Ubuntu Release Status
nginx 12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy
Not affected

Notes


tyhicks

Per Debian, naxsi package was introduced in 1.1.18-1


mdeslaur

precise and earlier don't ship naxsi-ui in any binary package, which is the vulnerable part.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
nginx