CVE-2017-18477: Medium severity cpanel vulnerability
Published Aug 5, 2019
·Updated
In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206).
Affected Software
5 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.36
Cpanel Cpanel>=55.9999.61<56.0.43
Cpanel Cpanel>=57.9999.48<58.0.43
Cpanel Cpanel>=59.9999.58<60.0.35
Cpanel Cpanel>=61.9999.55<62.0.4
Event History
Aug 5, 2019
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18477?
CVE-2017-18477 is considered a high severity vulnerability due to the potential unauthorized access to the Exim mail transport system.
2
How do I fix CVE-2017-18477?
To fix CVE-2017-18477, upgrade your cPanel version to 62.0.4 or later.
3
What versions of cPanel are affected by CVE-2017-18477?
CVE-2017-18477 affects cPanel versions prior to 62.0.4, including versions 55.9999.61 to 56.0.43, 57.9999.48 to 58.0.43, and 59.9999.58 to 60.0.35.
4
What are the risks associated with CVE-2017-18477?
The risks associated with CVE-2017-18477 include potential unauthorized execution of code and compromise of the nobody account on the server.
5
Is there any workaround for CVE-2017-18477?
There are no recommended workarounds for CVE-2017-18477; upgrading to the fixed version is the best course of action.