---
schema_version: '1.0'
id: security-20260705-49ad54
url: https://osv.dev/vulnerability/DEBIAN-CVE-2013-0337
url_hash: 49ad5485ce2ec058eface2b1e27d083b6f3a09e2e3b8b9e34e3608520f9083f3
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2013-0337
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2013-0337
- nginx
- Debian
lang: en
published_at: '2013-10-27T00:55:03Z'
fetched_at: '2026-07-05T15:34:33Z'
updated_at: '2026-07-05T15:34:51Z'
status: published
content_hash: 3ebe9bd91e6102d19f3101bf8ff58d21030491ea7693935276bbefe3f638ce4b
license_note: full
summary: The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable
  permissions for the (1) access.log and (2) error.log files, which allows local users
  to obtain sensitive information by reading the files.
summary_source: rss
summary_en: The default configuration of nginx, possibly 1.3.13 and earlier, uses
  world-readable permissions for the (1) access.log and (2) error.log files, which
  allows local users to obtain sensitive information by reading the files.
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2013-0337 — nginx
---

# DEBIAN-CVE-2013-0337 — nginx

## TL;DR
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.

## Key Points
- cve / DEBIAN-CVE-2013-0337 / nginx / Debian

## Details
**Advisory:** DEBIAN-CVE-2013-0337

**Affected (your watchlist):**
- `Debian:nginx` 1.22.1-9+deb12u1 → no fixed version listed [proxmox]

**Details:**
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the files.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2013-0337

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2013-0337_

## Source
元記事: [DEBIAN-CVE-2013-0337 — nginx](https://osv.dev/vulnerability/DEBIAN-CVE-2013-0337) — published 2013-10-27T00:55:03Z
