Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 10-18-2006, 05:35 PM
Active Member
 
Posts: 47
Default Zimbra Security Patches or Updates?

So... there is vulnerabilities in ClamAV... Is Zimbra planning on releasing and updated version of Zimbra with a patched ClamAV?

From Secunia:

A vulnerability has been reported in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a vulnerable system.

The vulnerability is caused due to a boundary error within the HTTP client in the Freshclam command line utility. This can be exploited to cause a stack-based buffer overflow when the HTTP headers received from a web server exceeds 8KB.

Successful exploitation requires that Freshclam is used to download virus signature updates from a malicious mirror web server e.g. via DNS poisoning.

The vulnerability has been reported in version 0.80 through 0.88.1.
Reply With Quote
  #2 (permalink)  
Old 10-18-2006, 05:52 PM
Project Contributor
 
Posts: 58
Default

Quote:
Originally Posted by illscientific
So... there is vulnerabilities in ClamAV... Is Zimbra planning on releasing and updated version of Zimbra with a patched ClamAV?

Successful exploitation requires that Freshclam is used to download virus signature updates from a malicious mirror web server e.g. via DNS poisoning.
I absolutely agree that every vulns should be fixed asap, so thanks for your post.
But secunia should be aware that if an antivirus can get updates from a malicious site, a dos attack is really the best thing that can happen!
Ciao
Claudio
Reply With Quote
  #3 (permalink)  
Old 10-19-2006, 04:00 AM
OpenSource Builder & Moderator
 
Posts: 1,166
Default

i think recent versions for a while have used 0.88.4, no?
Reply With Quote
  #4 (permalink)  
Old 10-19-2006, 06:03 AM
Special Member
 
Posts: 124
Default

0.88.5 is out.
Fixes issues with .chm files that I already block so, not a real big issue for me.
CLAMAV Upgrade is super simple anyway though so, I usually do right away just to get it done.

Scotty
Reply With Quote
  #5 (permalink)  
Old 10-19-2006, 11:00 AM
Active Member
 
Posts: 47
Default

I just really hope Zimbra takes vulnerabilities in the open source software they use to make their product seriously and it doesn't degenerate into listing mitigating circumstances or comming up with reasons they feel it is not necessary to fix rather than updating the software like most administrators would desire happen. This would be yet another reason to use Zimbra over Exchange.
Reply With Quote
  #6 (permalink)  
Old 10-19-2006, 02:32 PM
Special Member
 
Posts: 124
Default

Exchange has more holes than Zimbra does really. ;-)
Then, it's one of those YMMV vary things I guess.
For me, the couple of minutes I spend a day looking at the logs and such, doing a simple Anti-virus engine upgrade so far hasn't been a big issue.
Takes me two minutes now and done. So, not sure if Apple to Oranges comparison really.
Spend more time fixing and patching and maintaining Exchange and also a lot more $$$ by the time you add up all of the stuff you have to buy extra, I am willing to do a couple of things myself. Not many things have come out needed to be patched like RIGHT NOW for blatent security issues/holes other than clamav really. At least that I have seen since June of this year since I moved my mail over to Zimbra.

I do notice as the Zimbra version numbers increase, the underlying stuff does get upgraded. I am fairly sure that if I had the Network Edition ( have the free version ), they could SSH in and take care if it if I called. ( shrug )
With Exchange, I was subscribed to an Microsoft announce list but always found out it had a vulerability way before it was announced by them on cert and other websites so, not really seeing anything different, in that way, other than just me getting in there and taking care of patches when they come out.

Ya know?

Scotty
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.