cPanel 2012-05-31 security update
- https://secunia.com/advisories/49363/
Last Update: 2012-06-05
Criticality level: Moderately critical
Impact: Unknown
Where: From remote …
… vulnerabilities are reported in versions prior to 11.30.6.8, 11.32.2.28, and [removed].
Solution: Update to version 11.30.6.8, 11.32.2.28, or 11.32.3.19.
Software: cPanel 11.x
Original Advisory: http://go.cpanel.net/changelog
Security Release 2012-05-31 Announcement
May 31, 2012 - "cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system…"
SSHD rootkit in the wild
- https://isc.sans.edu/diary.html?storyid=15229
Last Updated: 2013-02-22 18:32:22 UTC
"UPDATE: Over the night (depending on where you live), a lot of things happened… cPanel also posted a notice to their users that they have been compromised… keep in mind – if your servers are infected with the SSHD rootkit, the attackers will get your passwords/keys *anyway*… So make sure that you check if your server has been compromised and that you clean it accordingly…"
- https://isc.sans.edu/diary/SSHD+rootkit+in+…d/15229#comment
Fri Feb 22 2013, 01:49 - "… just in from cpanel: Salutations… cPanel, Inc. has discovered that one of the servers we utilize in the technical support department has been compromised. While we do not know if your machine is affected, you should change your root level password if you are not already using ssh keys. If you are using an unprivileged account with "sudo" or "su" for root logins, we recommend you change the account password. Even if you are using ssh keys we still recommend rotating keys on a regular basis. As we do not know the exact nature of this compromise we are asking for customers to take immediate action on their own servers. cPanel's security team is continuing to investigate the nature of this security issue…"
cPanel & WHM 11.36, 11.34, and 11.32 Security Releases
- https://cpanel.net/important-cpanel-whm-11-…urity-releases/
Feb 26, 2013 - "cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system. cPanel has rated these updates as having important security impact. Information on security ratings is available at:
- http://go.cpanel.net/securitylevels
cPanel cpanellogd vulns - update available
- https://secunia.com/advisories/53921/
Release Date: 2013-07-08
Criticality: Moderately Critical
Where: From remote
Impact: Privilege escalation
… vulnerabilities are reported in versions prior to 11.38.1.4, 11.38.0.19, [removed], [removed], and [removed].
Solution: Update to version 11.38.1.4, 11.38.0.19, 11.36.1.9, 11.34.1.17, or 11.32.6.8.
Original Advisory: cPanel: http://cpanel.net/cpanel-security-disclosure-tsr-2013-0007/
cPanel updated …
- https://secunia.com/advisories/54455/
Release Date: 2013-08-14
Where: From remote
Impact: Hijacking, Manipulation of data
Solution Status: Vendor Patch
Software: cPanel 11.x
… vulnerabilities are reported in versions prior to 11.32.6.17, 11.34.1.25, 11.36.1.15, 11.38.1.13, and 11.39.0.5.
Solution: Update to version 11.32.6.17, 11.34.1.25, 11.36.1.15, 11.38.1.13, or 11.39.0.5.
Original Advisory: cPanel: http://cpanel.net/tsr-2013-0008-disclosure/
cPanel - updates available
- https://secunia.com/advisories/54601/
Release Date: 2013-09-03
Criticality: Moderately Critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege escalation, System access
Software: cPanel 11.x
… vulnerabilities… are reported in versions prior to 11.32.7.3, 11.34.2.4, [removed], [removed], and [removed].
Solution: Update to version 11.32.7.3, 11.34.2.4, 11.36.2.3, 11.38.2.6, or 11.39.0.15.
Original Advisory: cPanel: http://cpanel.net/sec-advisory-2013-08-27/
> http://cpanel.net/wp-content/uploads/2013/…dDisclosure.txt
cPanel CloudFlare Plugin - Privilege Escalation Vuln
- https://secunia.com/advisories/55273/
Release Date: 2013-10-18
Criticality: Moderately Critical
… vulnerability is reported in version 4.1. Prior versions may also be affected.
Solution: Update to version 4.2.
Original Advisory: Rack911: https://blog.rack911.com/security-advisorie…lity-r911-0080/
2013-10-15 - "… rated as CRITICAL due to the fact that root access can be obtained…"
cPanel updates …
- https://secunia.com/advisories/56146/
Release Date: 2013-12-20
Criticality: Moderately Critical
Where: From remote
Impact: Security Bypass, Cross Site Scripting, Manipulation of data, Exposure of sensitive information, Privilege escalation
Software: cPanel 11.x
CVE Reference: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6780
… security issue is reported in versions prior to 11.40.1.3, 11.40.0.29, and 11.38.2.13.
Solution: Update to version 11.40.1.3, 11.40.0.29, 11.38.2.13, or 11.36.2.10 or later.
Original Advisory: http://cpanel.net/tsr-2013-0011-announcement/
cPanel 11.40.1.7 released
- https://secunia.com/advisories/56207/
Release Date: 2013-12-24
Where: From remote
Impact: Exposure of sensitive information
Software: cPanel 11.x
CVE Reference: No CVE references.
… vulnerability has been reported in cPanel, which can be exploited by malicious users to disclose potentially sensitive information.
… vulnerability is reported in versions prior to 11.40.1.7, 11.40.0.31, [removed], and [removed].
Solution: Update to version 11.40.1.7, 11.40.0.31, 11.38.2.15, or 11.36.2.12 or later.
Original Advisory: TSR 2013-0012: http://cpanel.net/tsr-2013-0012-full-disclosure/ http://cpanel.net/tsr-2013-0012-announcement/
"… changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system. cPanel has rated these updates as having security impact levels of Important…"
- http://www.securitytracker.com/id/1029531
Dec 24 2013
Impact: Disclosure of system information, Disclosure of user information
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to versions 11.36.2.12, 11.38.2.15, [removed], [removed]
Solution: The vendor has issued a fix ([removed], 11.38.2.15, 11.40.0.31, 11.40.1.7).
The vendor's advisory is available at: http://cpanel.net/tsr-2013-0012-full-disclosure/
cPanel updates - TSR 2014-0003
- https://secunia.com/advisories/57576/
Release Date: 2014-04-01
Criticality: Moderately Critical
Where: From remote
Impact: Cross Site Scripting, Spoofing, Manipulation of data, Security Bypass, Exposure of sensitive information, System access …
Two weaknesses, a security issue, and multiple vulnerabilities have been reported in cPanel…
cPanel TSR 2014-0003
Original Advisory:
- http://cpanel.net/cpanel-tsr-2014-0003-full-disclosure/
"… issue is resolved in the following builds: 11.42.0.23, 11.40.1.13, 11.38.2.23 …"
cPanel updates released …
- https://secunia.com/advisories/58717/
Release Date: 2014-05-26
Criticality: Moderately Critical
Where: From remote
Impact: Unknown
Solution Status: Vendor Patch
Software: cPanel 11.x
… vulnerabilities are reported in versions prior to 11.43.0.12, 11.42.1.16, and [removed].
Solution:
Update to version 11.43.0.12, 11.42.1.16, or 11.40.1.14.
Original Advisory: cPanel:
- http://cpanel.net/cpanel-tsr-2014-0004-announcement/
May 19, 2014
___
cPanel TSR-2014-0005 …
- http://cpanel.net/cpanel-tsr-2014-0005-announcement/
July 21, 2014 - "cPanel has released new builds for all public update tiers. These updates provide targeted changes to address security concerns with the cPanel & WHM product. These builds are currently available to all customers via the standard update system. cPanel has rated these updates as having security impact levels ranging from Minor to Important… If your deployed cPanel & WHM servers are configured to automatically update when new releases are available, then no action is required. Your systems will update automatically. If you have disabled automatic updates, then we strongly encourage you to update your cPanel & WHM installations at your earliest convenience… The following cPanel & WHM versions address all known vulnerabilities:
* [removed] & Greater
* [removed] & Greater
* [removed] & Greater
* [removed] & Greater
The latest public releases of cPanel & WHM for all update tiers are available at - http://httpupdate.cpanel.net
… This Targeted Security Release addresses -22- vulnerabilities in cPanel & WHM software versions 11.44, 11.42, and 11.40…"
___
cPanel TSR-2014-0005 Full Disclosure
- http://cpanel.net/cpanel-tsr-2014-0005-full-disclosure/
July 28, 2014
Summary: Limited SQL injection vulnerability in LeechProtect.
Security Rating: cPanel has assigned a Security Level of Minor to this vulnerability…
Solution: This issue is resolved in the following builds:
11.44.1.5
11.44.0.29
11.42.1.23
11.40.1.18 …