Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
 
Go Back   Zimbra - Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra - Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old 07-01-2009, 07:34 PM
Advanced Member
 
Posts: 189
Default

I was just thinking the same thing. I logged onto my suppport account with Zimbra expecting to see something in there, but didn't. I started wondering the same thing wondering if I really wanted to apply that code to my server.

Zimbra is this for real?
__________________
Release 6.0.2_GA_1912.UBUNTU8_64 UBUNTU8_64 NETWORK edition + Mobile Option
Activesync with Moto Q9C, HTC Touch Pro, Palm Pro, & Palm Pre
Reply With Quote
  #12 (permalink)  
Old 07-01-2009, 07:38 PM
Advanced Member
 
Posts: 189
Default

ok, that's what I was thinking as well. I figured you might not want to make it public. It's just alarms started ringing when none of the URL's went back to Zimbra. Just being cautious. Thanks!
__________________
Release 6.0.2_GA_1912.UBUNTU8_64 UBUNTU8_64 NETWORK edition + Mobile Option
Activesync with Moto Q9C, HTC Touch Pro, Palm Pro, & Palm Pre
Reply With Quote
  #13 (permalink)  
Old 07-01-2009, 07:45 PM
Trained Alumni
 
Posts: 31
Thumbs up 7-1-09 security patch

In case anybody was waiting for some reports on this, we've applied it to our systems successfully- 5.0.16 on RHEL5-64.

Thanks to all involved for getting the word out and making the patch easy to apply!
Reply With Quote
  #14 (permalink)  
Old 07-01-2009, 09:13 PM
Partner (VAR/HSP)
 
Posts: 184
Smile Zimbra Security Vulnerability Report 2nd July

I received a Zimbra Security Vulnerability Report email today. Is this a hoax or for real? There is no mention of it in the forum announcements.

If real, will this precipitate a new Zimbra release? I really hate 'patching' a system.

Thanks!
__________________
http://agileware.net
Your Australian Zimbra experts
Sales, consulting, installation, support
Reply With Quote
  #15 (permalink)  
Old 07-01-2009, 09:21 PM
Trained Alumni
 
Posts: 190
Default

Information about the vulnerability can be found in the support portal, so I would say it's safe to say it's real.
Reply With Quote
  #16 (permalink)  
Old 07-01-2009, 09:25 PM
Zimbra Consultant
 
Posts: 5,814
Default

Valid & available in the portal https://support.zimbra.com

We apologize for the link url's in the notice emails being obscured through loopfuse / not pointing directly to files.zimbra or h.yimg and causing concerns over it's legitimacy.
__________________
-Mike Morse (MCode151)

ZCS-to-ZCS Migrations & Moves | Admin Tools & Tidbits » ZimbraBlog.com | ZimbraCommunity.com

Last edited by mmorse : 07-02-2009 at 03:40 PM.
Reply With Quote
  #17 (permalink)  
Old 07-02-2009, 07:39 AM
Active Member
 
Posts: 43
Default social engineering

We use ZCS Network Pro. We received a security notice last night from Zimbra advising us to install a patch. I verified the md5 checksum provided in the e-mail. However, the link to the update was directed to the server "loopfuse.net". After inspecting the headers, I saw the e-mail came from this domain as well. Only after looking further in the message source did I notice that the text version of the same e-mail actually provides direct links to the same patch hosted on "zimbra.com".

If zimbra expects administrators to replace important system files linked to through a third party in an e-mail, doesn't that leave them vulnerable to social engineering? If I had a copy of that same file except one that creates vulnerabilities instead of fixing them, I can send a similar e-mail to zimbra admins using a domain which sounds like it could be a marketing partner, tricking them into making their system wide open for attack.
Reply With Quote
  #18 (permalink)  
Old 07-02-2009, 08:18 AM
Intermediate Member
 
Posts: 18
Default Mailboxd security vulnerability?

Last night I received an email from Zimbra about a security vulnerability in the mailbox server with a link to download a patch. I was going to apply the patch, but it doesn't download from the Zimbra site, which made me a bit concerned. I haven't seen anything about this in the forums, or the Zimbra site. Is there any more information about this?

Does it just affect NE or the FOSS version as well. If it effects both, is there a FOSS patch somewhere?
Reply With Quote
  #19 (permalink)  
Old 07-02-2009, 08:51 AM
Member
 
Posts: 12
Question Security scam?

A few minutes ago there was a posting titled "Mailboxd security vulnerability?", that post is now gone. What's up with that? I have attached a picture of that post.

I did not receive this message but one of my end users did and has send it to me. I have looked at the headers on the message and it looks like it was sent from loopfuse.net. Is this a scam? The message looks good but the source is questionable and the download links are also pointed at loopfuse.

Picture 8.jpg
Reply With Quote
  #20 (permalink)  
Old 07-02-2009, 08:57 AM
Zimbra Consultant & Moderator
 
Posts: 11,506
Default

This post has been moderated until a formal forum announcement is made about this issue.
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

Zimbrablog.com




 

Search Engine Optimization by vBSEO 3.1.0