CVE-2016-10819: Medium severity Cpanel Cpanel vulnerability
Published Aug 1, 2019
·Updated
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
Affected Software
4 affected components
Cpanel Cpanel>=11.50.0.4<11.50.6.2
Cpanel Cpanel>=11.52.6.0<11.52.6.1
Cpanel Cpanel>=11.54.0.0<11.54.0.24
Cpanel Cpanel>=56.0.1<56.0.15
Event History
Aug 1, 2019
CVE Published
via MITRE·06:31 PM
Data Sourced
via MITRE·06:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10819?
CVE-2016-10819 is considered to be a moderate severity vulnerability as it allows sensitive user log files to become world-readable.
2
How do I fix CVE-2016-10819?
To fix CVE-2016-10819, update cPanel to version 58.0 or later.
3
What are the affected versions for CVE-2016-10819?
CVE-2016-10819 affects cPanel versions before 57.9999.54, including certain versions within 11.50, 11.52, 11.54, and 56.x.
4
What type of vulnerability is CVE-2016-10819?
CVE-2016-10819 is a file permission vulnerability that exposes user log files due to incorrect log rotation.
5
Who is affected by CVE-2016-10819?
Anyone using the affected versions of cPanel prior to the fix is at risk of having their user log files made world-readable.