CVE-2017-18045: Critical severity directadmin vulnerability
Published Jan 21, 2018
·Updated
JBMC DirectAdmin before 1.52, when the emailftppasswordchange setting is nonzero, allows remote attackers to obtain access or cause a denial of service (segfault) via an unspecified request.
Affected Software
1 affected component
DirectAdmin DirectAdmin<1.52
Event History
Jan 21, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18045?
CVE-2017-18045 has been classified as a medium severity vulnerability due to its potential for exploitation by remote attackers.
2
How do I fix CVE-2017-18045?
To fix CVE-2017-18045, upgrade DirectAdmin to version 1.52 or later.
3
What impacts does CVE-2017-18045 have on affected systems?
CVE-2017-18045 can allow remote attackers to gain unauthorized access or cause denial of service through segmentation faults.
4
Which versions of DirectAdmin are affected by CVE-2017-18045?
CVE-2017-18045 affects DirectAdmin versions before 1.52.
5
What configurations should be checked in relation to CVE-2017-18045?
Check the email_ftp_password_change setting, as it can influence the vulnerability's exploitation.