Get our latest news

Blog & News

EasyApache 3 Security Release

  • 17 December 2018

The cPanel team has released EasyApache 3.36.11 with PHP version 5.6.39. This security update addresses vulnerabilities related to CVE-2018-19518 and CVE-2018-19935. It is highly recommended for all PHP 5.6 users to upgrade to version 5.6.39. Unless you have disabled EasyApache updates, the EasyApache application updates to the latest version when launched. Run EasyApache to rebuild your profile with the latest version of PHP.
 

Affected versions

All versions of PHP 5.6 through 5.6.38
 

Security ratings

The National Vulnerability Database (NIST) has given the following severity ratings to these CVEs:

  • CVE-2018-19518 – MEDIUM; PHP 5.6.39; Fixed bug in IMAP module related to CVE-2018-19518
  • CVE-2018-19935 – MEDIUM; PHP 5.6.39; Fixed bug in IMAP module related to CVE-2018-19935


References

For more information, please make sure to visit the release notes and the official EasyApache 3 changelog.