• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Questions on latest security bulletin

HostaHost

Regular Pleskian
Today's bulletin, which references http://kb.parallels.com/114377, states that there are updates available for:

10.4.x
10.3.x
10.2.x
10.1.x
10.0.x
9.5.x
9.3.x
9.2.x
9.0.x
8.6.x
8.4.x
8.2.x

yet the autoinstaller only seems to know about updates for 10.4.x, 9.5.4 and 8.6. It reports nothing available for all the other versions. Does that mean the other versions are all vulnerable or that they were never vulnerable to begin with? Why is there NO information published about what actual files, and what file versions, are vulnerable so that people responsible for the security of the servers can check their status?
 
Try updating from the parallels server as source directly with the command

/usr/local/psa/admin/sbin/autoinstaller --source=http://64.131.90.31
 
Try updating from the parallels server as source directly with the command

/usr/local/psa/admin/sbin/autoinstaller --source=http://64.131.90.31

Didn't change things. They claim their releases cover a variety of versions but apparently that is not the case, and I'm still waiting for them to actually provide documentation on what their microupdates replace so we can systematically verify every server is patched regardless of what the often broken autoinstaller and update servers say.
 
There are custom fixes for those version outside of the ones support by the microfixes.

check the page again, and possible clear your browser cache first.

There is a table including all the fixes, which wasn't there when the page first went up.
 
Back
Top