• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

Upgrade psa-proftpd {1.3.1}, SQL injection vulnerability

psa-proftpd won't upgrade

Hello -

I have Plesk 8.6, and run the hotfix, so maybe I'm OK. I was hacked with this vulnerability. However, psa-proftpd is still at 1.3.1.

When I try to upgrade to 1.3.4 w/ the atomic repo, I get:

Transaction Check Error:
file /etc/proftpd.conf from install of psa-proftpd-1.3.4a-1.el5.art.x86_64 conflicts with file from package psa-proftpd-xinetd-1.3.1-cos5.build86080722.00.x86_64
file /etc/xinetd.d/ftp_psa from install of psa-proftpd-1.3.4a-1.el5.art.x86_64 conflicts with file from package psa-proftpd-xinetd-1.3.1-cos5.build86080722.00.x86_64

If I try to remove 1.3.1, yum wants to remove over 100 packages because of dependencies, so think that's too risky.

Is there a way around this to upgrade to 1.3.4?

I haven't seen any more hacks since applying the hotfix, but maybe they're just resting.

Thanks for any info.
 
Back
Top