• The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Some vulnerabilities found. Help me to patch it

Leo1

New Pleskian
Hi Parallels,

I am having a Plesk server and when I scanned it with tools like OpenVas, It detected the following vulnerabilities with CVE acronym. As the corresponding ports and services are being controlled by Plesk, I require your help to patch it.

http://prntscr.com/67oxzt

As you can see this vulnerability has been hit on port 106. I checked the Plesk server and found the port 106 being used by service "poppassd". This was nothing I installed and came along with the Plesk installation. Hence just wanted to make sure whether it has a patch from Parallels. As per my investigation this service is used for changing mailbox passwords and I am currently using Roundcube client. Please help me to patch this vulnerability. If this just a false alarm, please let me know.

I have one more concern. http://prntscr.com/67ozf9

As per the solution in pic, the vulnerability "SMTP antivirus scanner DoS" can be resolved by upgrading or installing anti virus for Plesk mail server. I am ready to buy Dr.Web or Kaspersky from Parallels. But wanted to make sure whether any of the above antivirus can resolve the vulnerability.

Please let me know the above can be resolved with a proper panel upgrade to 12.

cat /usr/local/psa/version
11.0.9 CentOS 6 110120608.16


Thanks and Regards,
Leo Prince.
 
Hi forum moderator,

Can I have this thread approved.. I am waiting for a solution.

Thanks..
 
Back
Top