• If you are still using CentOS 7.9, it's time to convert to Alma 8 with the free centos2alma tool by Plesk or Plesk Migrator. Please let us know your experiences or concerns in this thread:
    CentOS2Alma discussion

ProFTPD 1.3.3e - PCI complian scan failed

S

snowfire

Guest
ProFTPD 1.3.3e - PCI compliance scan failed

Hello
I just completed a clients container upgrade from 10.3 to 10.4.4 (media Temple Plesk Parallels panel) specifically to fix the issue with ProFTPD.
I just ran a new pci scan, and it failed on ProFtpD( http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4130), It lists the solution as "upgrade to 1.3.3g".
current version: psa-proftpd 1.3.3e-cos5.build1013111101.14
according to the knowledgebase(http://www.parallels.com/products/plesk/documentation/proftpd/) the current version should be fine, is this true, should I contact security metrics and submit some type of mitigation?

Is this version available for upgrade? would I have to do a command line micro upgrade (my panel does not list any upgrades for the container)?
thank you for your help
 
Last edited by a moderator:
thanks for the update burnleyvic.
can any one at plesk please address this, is there an update to 1.3.3 g, or 1.3.4?
my client is very insistent that this get fixed asap, because their shopping cart is currently not pci compliant.
thank you
 
Agreed

Yea,

This was what our hosting company recommended as well...
Uh, kind of defeats the point of having a hosting company/using Plesk.
I should have just gone with Amazon.
 
thanks for the link, works like a champ & will be careful of the microupdates...
 
did that patch update you to 1.3.3g?
I haven't tried it yet myself, just found it. any issues with ftp afterwards?
 
Back
Top