Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
May 21, 2012, 03:49:00 AM

Pages: [1]   Go Down
  Print  
Author Topic: ProFTPD Remote Code Execution Vulnerability  (Read 1809 times)
perestrelka
Administrator
Master Jedi
*****
Offline Offline

Posts: 1395



« on: November 11, 2010, 12:48:15 PM »

Dear Customers,

If you are running a Linux server with Plesk control panel,  please be aware there was a flaw discovered in the popular ProFTPD FTP server that potentially allows unauthenticated attackers to compromise your server. The problem is caused by a buffer overflow in the pr_netio_telnet_gets() function for evaluating TELNET IAC sequences.

ProFTPD bug report: http://bugs.proftpd.org/show_bug.cgi?id=3521

Updating to ProFTPD version 1.3.3c or disabling FTP services is the only current solution to this vulnerability.

A Proftpd update for Plesk has been provided by Atomic Rocket Turtle (http://www.atomicorp.com/news/security-update.html). To apply the update, execute the commands below.

Code:
wget -O - http://www.atomicorp.com/installers/atomic | sh
yum upgrade psa-proftpd

Please review http://www.parallels.com/products/plesk/ProFTPD for updates to this security issue.

We can perform this upgrade for you for a fee of $35. You would simply need to contact dedicated@lunarpages.com with the last 4 digits of your card on file and your account username or primary domain name.

Those who are on managed hosting, please note we can provide this update by your request at no cost.

If you have any questions, please contact dedicated@lunarpages.com with those questions.

Thank you,
Lunarpages System Administrator Team
« Last Edit: November 11, 2010, 12:50:16 PM by perestrelka » Logged

Kind Regards,
Vlad Artamonov
perestrelka
Administrator
Master Jedi
*****
Offline Offline

Posts: 1395



« Reply #1 on: November 12, 2010, 12:41:52 AM »


Parallels has used its micro-update patch functionality in Plesk 9.5x and 10.x to fix this exploit. You can run the Parallels AutoInstaller to fix this or check the Updates section of your Plesk Panel 9.5x or 10.x to fix this. This is a file-replace, as opposed to a new install so it will be quick and reliable. To find this in the GUI:

Parallels Plesk Panel 9.5x: “Home” -> “Updates” -> Select the Panel version which has updates -> click “Install” ?
Parallels Plesk Panel 10.x:“Server Management” -> “Tools & Utilities” -> “Updates” -> “Update Components” -> click “Continue”
Logged

Kind Regards,
Vlad Artamonov
Pages: [1]   Go Up
  Print  
 
Jump to: