First published: Thu Aug 01 2019(Updated: )
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cpanel Cpanel | >=11.50.0.4<11.50.6.2 | |
Cpanel Cpanel | >=11.52.6.0<11.52.6.1 | |
Cpanel Cpanel | >=11.54.0.0<11.54.0.24 | |
Cpanel Cpanel | >=56.0.1<56.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10819 is considered to be a moderate severity vulnerability as it allows sensitive user log files to become world-readable.
To fix CVE-2016-10819, update cPanel to version 58.0 or later.
CVE-2016-10819 affects cPanel versions before 57.9999.54, including certain versions within 11.50, 11.52, 11.54, and 56.x.
CVE-2016-10819 is a file permission vulnerability that exposes user log files due to incorrect log rotation.
Anyone using the affected versions of cPanel prior to the fix is at risk of having their user log files made world-readable.