22-feb-2012, 20:28
|
#1 (permalink)
|
| Usuario activo
Fecha de Ingreso: abril-2007 Ubicación: España - Perú
Mensajes: 3.840
| [FIX] Remote vulnerability in Plesk Panel
Problema de seguridad en Plesk, afecta a todas las versiones. Cita:
[FIX] Remote vulnerability in Plesk Panel
Article ID: 113321 (edit)
Last Review: Feb, 22 2012
Author: Gubaidullin Igor
Last updated by: DeShawn
Views:
Useful:
APPLIES TO:
Plesk 9.x for Linux/Unix
Plesk 8.x for Linux/Unix
Plesk 9.x for Windows
Plesk 8.x for Windows
Plesk 10.0.x for Windows
Plesk 10.1 for Windows
Plesk 10.2 for Windows
Plesk 10.3 for Windows
Plesk 10.0.x for Linux/Unix
Plesk 10.1 for Linux/Unix
Plesk 10.2 for Linux/Unix
Plesk 10.3 for Linux/Unix
Description
NOTE: The issue has been completely fixed in Plesk 8.6 MU#2, 9.5 MU#11, 10.3 MU#5 and later.
Anonymous attacker can remotely compromise Plesk server through API RPC.
Severity of vulnerability: Critical
Access Vector: Network exploitable; Victim must voluntarily interact with attack mechanism
Access Complexity: easy
Authentication: Not required to exploit
Impact Type: Allows unauthorized access and modification
Vulnerable versions: Parallels Plesk Panel 7.6.1 - 10.3.1 version
Recommended resolution path for providers and large datacenters
update or migrate Plesk to versions where Micro-Updates with fixes are available.
manual files replacement
use workaround (see below)
Resolution
For the versions
Plesk 8.2 for Linux/Unix
Plesk 8.4 for Linux/Unix
Plesk 9.0 for Linux/Unix
Plesk 9.2.x for Linux/Unix
Plesk 9.3 for Linux/Unix
Plesk 10.0.x for Linux/Unix
Plesk 10.1 for Linux/Unix
Plesk 10.2 for Linux/Unix
apply fixes from KB article http://kb.parallels.com/en/113313
For the versions
Plesk 8.2 for Windows
Plesk 8.4 for Windows
Plesk 8.6 for Windows
Plesk 9.0 for Windows
Plesk 9.2 for Windows
Plesk 9.3 for Windows
Plesk 9.5 for Windows
apply fixes from KB article http://kb.parallels.com/en/112303
For the versions
Plesk 8.6 for Linux
Plesk 9.5.4 for Linux
Plesk 10.0.1 for Linux and Windows
Plesk 10.1.1 for Linux and Windows
Plesk 10.2.0 for Linux and Windows
Plesk 10.3.1 for Linux and Windows
fixes provided by the Micro-Updates:
8.6.0 for Linux only MU#2 - http://kb.parallels.com/en/112181
9.5.4 for Linux only MU#11 - http://kb.parallels.com/en/112179
10.0.1 for Linux and Windows MU#13 - http://kb.parallels.com/en/113322
10.1.1 for Linux and Windows MU#22 - http://kb.parallels.com/en/113323
10.2.0 for Linux and Windows MU#16 - http://kb.parallels.com/en/113324
10.3.1 for Linux and Windows MU#5 - KB is absent
For the remaining versions
Plesk 7.x Linux/Windows
Plesk 8.0 Linux
Plesk 8.1 Linux/Windows
Plesk 8.3 Linux/Windows
it's recommended to update to at least next nearest version available above.
| |
| |