Products

EasyApache 18 July 2017 Maintenance Release

SUMMARY cPanel, Inc. has released updated RPMs for EasyApache 4 on July 18, 2017, with Apache version 2.4.27. This release addresses vulnerabilities related to CVE-2017-7679, CVE-2017-7668, CVE-2017-7659, CVE-2017-3169, and CVE-2017-3167. We strongly encourage all Apache 2.4 users to upgrade to version 2.4.27. AFFECTED VERSIONS All versions of Apache 2.4 through …

EasyApache 18 July 2017 Maintenance Release Read More »

cPanel TSR-2017-0004 Full Disclosure

cPanel TSR-2017-0004 Full Disclosure SEC-263 Summary Stored XSS during WHM cPAddons install. Security Rating cPanel has assigned this vulnerability a CVSSv3 score of 3.9 CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N Description It was possible for an attacker to actively inject HTML into the WHM cPAddons screen during a moderated install. Credits This issue was discovered …

cPanel TSR-2017-0004 Full Disclosure Read More »

EasyApache 12 July 2017 Maintenance Release

SUMMARY cPanel, Inc. has released updated RPMs for EasyApache 4 on July 12, 2017, with PHP versions 5.6.31, 7.0.21, and 7.1.7. This release addresses vulnerabilities related to CVE-2017-9224, CVE-2017-9226, CVE-2017-9227, CVE-2017-9228, CVE-2017-9229, and CVE-2017-7890. We strongly encourage all PHP 5.6 users to upgrade to version 5.6.31, all PHP 7.0 users …

EasyApache 12 July 2017 Maintenance Release Read More »

cPanel TSR-2017-0003 Full Disclosure

cPanel TSR-2017-0003 Full Disclosure SEC-234 Summary Horde MySQL to SQLite conversion can leak database password. Security Rating cPanel has assigned this vulnerability a CVSSv3 score of 2.2 CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N Description If the Horde MySQL to SQLite conversion script requires a password reset on the MySQL database, the new password was passed …

cPanel TSR-2017-0003 Full Disclosure Read More »