CVE-2017-18434: Input Validation
Published Aug 2, 2019
·Updated
cPanel before 64.0.21 allows code execution in the context of the root account via a SETVHOSTLANGPACKAGE multilang adminbin call (SEC-237).
Affected Software
5 affected components
Cpanel Cpanel>=55.9999.61<56.0.49
Cpanel Cpanel>=57.9999.48<58.0.49
Cpanel Cpanel>=59.9999.58<60.0.43
Cpanel Cpanel>=61.9999.55<62.0.24
Cpanel Cpanel>=63.9999.74<64.0.21
Event History
Aug 2, 2019
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18434?
CVE-2017-18434 has a critical severity level due to its potential for code execution in the context of the root account.
2
How do I fix CVE-2017-18434?
To fix CVE-2017-18434, upgrade your cPanel installation to version 64.0.21 or later.
3
Which versions of cPanel are affected by CVE-2017-18434?
CVE-2017-18434 affects cPanel versions before 64.0.21, including 55.9999.61 to 56.0.49, 57.9999.48 to 58.0.49, 59.9999.58 to 60.0.43, and 61.9999.55 to 62.0.24.
4
Is CVE-2017-18434 exploit mitigated in later versions of cPanel?
Yes, CVE-2017-18434 is mitigated in cPanel version 64.0.21 and later, where the vulnerability has been addressed.
5
What type of vulnerability is CVE-2017-18434?
CVE-2017-18434 is a remote code execution vulnerability that occurs through a multilang adminbin call.