Hello, Everyone.
We strongly recommend to apply the following Micro-updates that should resolve the issue described in the thread:
http://kb.parallels.com/115018 - Parallels Plesk Panel 8.6.0 MU#20
http://kb.parallels.com/115017 - Parallels Plesk Panel 9.5.4 MU#26...
Hello, add1.
It's a good idea. Have you tried it?
We are working now on implementing similar approach to reduce downtime. I'll share results when we finish.
Not quite. Plesk ships patched Courier IMAP 3.0.8 that is not vulnerable. So it's securely.
SystemMetrics and some other PCI scanners don't actually check software for vulnerabilities but make decision based on indirect indicators. We have hidden these indicators.
The update makes something that PCI scanners should not fail on scanning Courier IMAP.
Courier IMAP will be updated to 4.11 in Plesk in further updates. ETA Q4'12.
Here you are. Patches and compiling options attached.
Plesk Service is working on the update that should silent PCI scanners. It's expected next week.
Also, as IgorG said above, Courier IMAP will be updated to 4.11 in further updates. ETA Q4'12.
--
Hello, Everyone. Thanks for reporting.
Could you, please, let us know which PCI scanners are reporting the issue to you?
Couple of ones would be enough for verifying. Thanks.
Could you, please, let us know exact step-by-step scenario how to reproduce? Also we need your real SSL certificate to check the issue.
Please send PM to me or IgorG.