CVE-2017-18389: Medium severity cpanel vulnerability
Published Aug 2, 2019
·Updated
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
Affected Software
3 affected components
Cpanel Cpanel>=63.9999.74<64.0.42
Cpanel Cpanel>=65.9999.38<66.0.34
Cpanel Cpanel>=67.9999.64<68.0.15
Event History
Aug 2, 2019
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18389?
CVE-2017-18389 is considered a medium severity vulnerability due to the potential for exploit using string format injection.
2
How do I fix CVE-2017-18389?
To fix CVE-2017-18389, update cPanel to version 68.0.15 or later.
3
What versions of cPanel are affected by CVE-2017-18389?
CVE-2017-18389 affects cPanel versions before 68.0.15, and also versions 64.0.42 and 66.0.34.
4
What type of attack does CVE-2017-18389 enable?
CVE-2017-18389 enables string format injection attacks that could compromise system integrity.
5
Who is impacted by CVE-2017-18389?
Users and administrators of cPanel versions prior to 68.0.15 are directly impacted by CVE-2017-18389.