CVE-2016-10799: Medium severity Cpanel Cpanel vulnerability
Published Aug 7, 2019
·Updated
cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137).
Affected Software
4 affected components
Cpanel Cpanel>=11.51.9999.98<11.52.6.2
Cpanel Cpanel>=11.54.0.0<11.54.0.26
Cpanel Cpanel>=55.9999.61<56.0.27
Cpanel Cpanel>=57.9999.48<58.0.4
Event History
Aug 7, 2019
CVE Published
via MITRE·12:21 PM
Data Sourced
via MITRE·12:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10799?
The severity of CVE-2016-10799 is classified as low, as it may lead to temporary file handling issues during PHP installations in cPanel.
2
How do I fix CVE-2016-10799?
To fix CVE-2016-10799, upgrade to cPanel version 58.0.4 or later, which properly sets the Pear tmp directory.
3
What systems are affected by CVE-2016-10799?
CVE-2016-10799 affects cPanel versions prior to 58.0.4, as well as specific versions of cPanel between 55.x, 56.x, and 57.x.
4
What happens if I do not address CVE-2016-10799?
If CVE-2016-10799 is not addressed, it could lead to issues with PHP installations not properly handling temporary files.
5
Is CVE-2016-10799 a common vulnerability?
CVE-2016-10799 is specific to certain versions of cPanel and may not be common outside of those specific environments.