Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-26-2009, 07:48 AM
Member
 
Posts: 13
Exclamation 7-1-09 security patch

I would like to disclose a vulnerability I discovered in Zimbra which needs to be patched urgently.

4.5, 5.0.16GA and 6 Beta 2 are all affected.

The initial response from support@zimbra.com has been unhelpful and I do not want to report this on your public bugtracker.

Please contact me at hubert at itsecurity.net

Last edited by Hubert; 06-26-2009 at 07:55 AM..
Reply With Quote
  #2 (permalink)  
Old 06-26-2009, 10:01 AM
New Member
 
Posts: 4
Default

I commend you for trying to handle this in a responsible manner.

Last edited by zombiewithamasseffect; 06-26-2009 at 03:39 PM..
Reply With Quote
  #3 (permalink)  
Old 06-26-2009, 11:42 AM
Member
 
Posts: 13
Default

I have done some more research on this with a colleague and the issue is highly critical.

If you have Zimbra HTTP(S) and SSH exposed to the internet, your installation can be compromised.

As a workaround I would highly recommend firewalling remote access to the SSH port, although this does not fully address the issue.

Still waiting to be contacted by Zimbra...
Reply With Quote
  #4 (permalink)  
Old 06-26-2009, 11:55 AM
Moderator
 
Posts: 7,911
Default

I have moderated this post until one of the employees respond; this is for the safety on the community.
__________________
Reply With Quote
  #5 (permalink)  
Old 06-26-2009, 12:08 PM
Zimbra Employee
 
Posts: 571
Default

Quote:
Originally Posted by uxbod View Post
I have moderated this post until one of the employees respond; this is for the safety on the community.
I'm trying to get the details offline.

--Quanah
__________________
Quanah Gibson-Mount
Sr. Member of Technical Staff
Zimbra, Inc
A Division of VMware, Inc.
--------------------
Zimbra :: the leader in open source messaging and collaboration
Reply With Quote
  #6 (permalink)  
Old 06-26-2009, 12:25 PM
raj raj is offline
Moderator
 
Posts: 758
Default

http://itsecurity.net
dont open..is this for real?

Raj
__________________
i2k2 Networks
Dedicated & Shared Zimbra Hosting Provider
Reply With Quote
  #7 (permalink)  
Old 06-26-2009, 01:15 PM
Moderator
 
Posts: 441
Default

itsecurity.net doesn't resolve. It is the MX record for the domain, so if he's expecting someone to email him, he's not going to get it.
Reply With Quote
  #8 (permalink)  
Old 06-26-2009, 05:11 PM
Member
 
Posts: 13
Default

My domain should be working again now (it has nothing about this bug on it at this time).

Yes it's real, Zimbra have confirmed the issues and are working on a patch.

Last edited by Hubert; 06-26-2009 at 05:13 PM..
Reply With Quote
  #9 (permalink)  
Old 07-01-2009, 02:12 AM
Former Zimbran
 
Posts: 5,606
Default

I'm re moderating this post. We have been in contact with the reporter, and are actively investigating and patching the issue.

Once we announce it, this thread will be republished.
Reply With Quote
  #10 (permalink)  
Old 07-01-2009, 07:26 PM
Member
 
Posts: 10
Default Security Vulnerability

I received email apparently from support@zimbra.com indicating that all current versions of Zimbra have a security vulnerability. The email had instructions and a download link for a patch. Problem is, the email was sent through a mailing list company and I can't verify that Zimbra sent it. Second, there is no reference (that I can find) in the forums or web site about this.

There is no way I'm installing this without something on the web site.

Is this a forgery or does Zimbra not have a clue how to alert their users?
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.