T
thekman
Guest
We are currently running Plesk 10.3.1 and are aware of the need to update our server to fix CVE-2009-3555 (RFC 5746) SSL/TLS vulnerability. I have seen a few posts from last year when people tried to update Plesk 9 and found a raft of problems which were later resolved, however we are on 10.3.1 and still have this problem. I believe it has something to do with requiring the latest mod_ssl which is part of apach 2 however my knowledge in this area is not great.
I have tried executing as root > yum update mod_ssl however I am told that no updates are available.
One thought I had is that like many people I too have Plesk 10.3.1 components that will not install and wondered if that might be the cause of why apache / mod_ssl isn't already updated.
It is very important to us to perform this update as our customers are complaining of warnings in firefox's error console about our ecommerce website being vulnerable to MIM type attacks.
I would be grateful if someone from Plesk could confirm whether 10.3.1 should already have the latest apache / mod_ssl versions which implement RFC 5746. If you could also find a solution to the components not updating problem that would be great too.
Many thanks,
thekman.
I have tried executing as root > yum update mod_ssl however I am told that no updates are available.
One thought I had is that like many people I too have Plesk 10.3.1 components that will not install and wondered if that might be the cause of why apache / mod_ssl isn't already updated.
It is very important to us to perform this update as our customers are complaining of warnings in firefox's error console about our ecommerce website being vulnerable to MIM type attacks.
I would be grateful if someone from Plesk could confirm whether 10.3.1 should already have the latest apache / mod_ssl versions which implement RFC 5746. If you could also find a solution to the components not updating problem that would be great too.
Many thanks,
thekman.