| Welcome to the Zimbra - Forums! | |
Welcome, if you would like to post a comment please register.
We also encourage you to explore all things Zimbra with our team and members of the community.
|  | | 
07-01-2009, 07:34 PM
| | Advanced Member | |
Posts: 188
| | I was just thinking the same thing. I logged onto my suppport account with Zimbra expecting to see something in there, but didn't. I started wondering the same thing wondering if I really wanted to apply that code to my server.
Zimbra is this for real?
__________________
Release 6.0.2_GA_1912.UBUNTU8_64 UBUNTU8_64 NETWORK edition + Mobile Option
Activesync with Moto Q9C, HTC Touch Pro, Palm Pro, & Palm Pre
| 
07-01-2009, 07:38 PM
| | Advanced Member | |
Posts: 188
| | ok, that's what I was thinking as well. I figured you might not want to make it public. It's just alarms started ringing when none of the URL's went back to Zimbra. Just being cautious. Thanks!
__________________
Release 6.0.2_GA_1912.UBUNTU8_64 UBUNTU8_64 NETWORK edition + Mobile Option
Activesync with Moto Q9C, HTC Touch Pro, Palm Pro, & Palm Pre
| 
07-01-2009, 07:45 PM
| | | 7-1-09 security patch In case anybody was waiting for some reports on this, we've applied it to our systems successfully- 5.0.16 on RHEL5-64.
Thanks to all involved for getting the word out and making the patch easy to apply! | 
07-01-2009, 09:13 PM
| | Partner (VAR/HSP) | |
Posts: 184
| | Zimbra Security Vulnerability Report 2nd July I received a Zimbra Security Vulnerability Report email today. Is this a hoax or for real? There is no mention of it in the forum announcements.
If real, will this precipitate a new Zimbra release? I really hate 'patching' a system.
Thanks!
__________________ http://agileware.net
Your Australian Zimbra experts Sales, consulting, installation, support | 
07-01-2009, 09:21 PM
| | Trained Alumni | |
Posts: 190
| | Information about the vulnerability can be found in the support portal, so I would say it's safe to say it's real. | 
07-01-2009, 09:25 PM
| | Zimbra Consultant | |
Posts: 5,784
| | Valid & available in the portal https://support.zimbra.com
We apologize for the link url's in the notice emails being obscured through loopfuse / not pointing directly to files.zimbra or h.yimg and causing concerns over it's legitimacy.
Last edited by mmorse : 07-02-2009 at 03:40 PM.
| 
07-02-2009, 07:39 AM
| | | social engineering We use ZCS Network Pro. We received a security notice last night from Zimbra advising us to install a patch. I verified the md5 checksum provided in the e-mail. However, the link to the update was directed to the server "loopfuse.net". After inspecting the headers, I saw the e-mail came from this domain as well. Only after looking further in the message source did I notice that the text version of the same e-mail actually provides direct links to the same patch hosted on "zimbra.com".
If zimbra expects administrators to replace important system files linked to through a third party in an e-mail, doesn't that leave them vulnerable to social engineering? If I had a copy of that same file except one that creates vulnerabilities instead of fixing them, I can send a similar e-mail to zimbra admins using a domain which sounds like it could be a marketing partner, tricking them into making their system wide open for attack. | 
07-02-2009, 08:18 AM
| | Intermediate Member | |
Posts: 18
| | Mailboxd security vulnerability? Last night I received an email from Zimbra about a security vulnerability in the mailbox server with a link to download a patch. I was going to apply the patch, but it doesn't download from the Zimbra site, which made me a bit concerned. I haven't seen anything about this in the forums, or the Zimbra site. Is there any more information about this?
Does it just affect NE or the FOSS version as well. If it effects both, is there a FOSS patch somewhere? | 
07-02-2009, 08:51 AM
| | | Security scam? A few minutes ago there was a posting titled "Mailboxd security vulnerability?", that post is now gone. What's up with that? I have attached a picture of that post.
I did not receive this message but one of my end users did and has send it to me. I have looked at the headers on the message and it looks like it was sent from loopfuse.net. Is this a scam? The message looks good but the source is questionable and the download links are also pointed at loopfuse. Picture 8.jpg | 
07-02-2009, 08:57 AM
| | Zimbra Consultant & Moderator | |
Posts: 11,333
| | This post has been moderated until a formal forum announcement is made about this issue.
__________________
Regards
Bill
| | Thread Tools | | | | Display Modes | Linear Mode | | Why Join? Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.  |