CVE-2017-18430: Input Validation
Published Aug 2, 2019
·Updated
In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassignpostterminatecruft (SEC-294).
Affected Software
6 affected components
Cpanel Cpanel>=55.9999.61<56.0.51
Cpanel Cpanel>=57.9999.48<58.0.52
Cpanel Cpanel>=59.9999.58<60.0.45
Cpanel Cpanel>=61.9999.55<62.0.27
Cpanel Cpanel>=63.9999.74<64.0.33
Cpanel Cpanel>=65.9999.38<66.0.2
Event History
Aug 2, 2019
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18430?
CVE-2017-18430 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2017-18430?
To fix CVE-2017-18430, update cPanel to version 66.0.2 or later.
3
What versions of cPanel are affected by CVE-2017-18430?
CVE-2017-18430 affects cPanel versions before 66.0.2, specifically versions between 55.9999.61 and 66.0.1.
4
What exploit does CVE-2017-18430 present?
CVE-2017-18430 may allow incorrect user and group ownership to be set when reassigning post-termination cruft.
5
Is CVE-2017-18430 related to cPanel security issues?
Yes, CVE-2017-18430 is related to security misconfigurations in cPanel that can lead to ownership issues.