CVE-2016-10798: Race Condition
Published Aug 7, 2019
·Updated
cPanel before 58.0.4 allows a file-ownership change (to nobody) via rearrangeacct (SEC-134).
Affected Software
2 affected components
Cpanel Cpanel>=55.9999.61<56.0.27
Cpanel Cpanel>=57.9999.48<58.0.4
Event History
Aug 7, 2019
CVE Published
via MITRE·12:20 PM
Data Sourced
via MITRE·12:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10798?
CVE-2016-10798 is considered a moderate severity vulnerability due to its potential to allow unauthorized file-ownership changes.
2
How do I fix CVE-2016-10798?
To fix CVE-2016-10798, update cPanel to version 58.0.4 or later.
3
What versions of cPanel are affected by CVE-2016-10798?
CVE-2016-10798 affects cPanel versions before 58.0.4 and those within the ranges of 55.9999.61 to 56.0.27 and 57.9999.48 to 58.0.4.
4
What is the impact of CVE-2016-10798?
The impact of CVE-2016-10798 includes unauthorized alteration of file ownership, potentially compromising security and access controls.
5
Who is affected by CVE-2016-10798?
Any users running vulnerable versions of cPanel prior to 58.0.4 are affected by CVE-2016-10798.