Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #11 (permalink)  
Old 12-21-2006, 12:34 PM
Project Contributor
 
Posts: 203
Default

Quote:
Originally Posted by martinfst View Post
And DSPAM and MySQL and ....
Even Postfix gets regular updates ..... It's now at 2.3 Patchlevel 5 and Zimbra uses 2.2.9. Not sure about CVE's....

Guess we need some kind of voting thread with all packages to be selected and get an impression from the community of which packages should be "separate".
Whoops! DSPAM yes, I forgot about that.

In general, I would consider packages that are directly exposed to the internet to be the ones I'm worried about as well as things that are indirectly exposed like AmavisD-New/ClamAV/SA/DSPAM because they are processing spam/virus/trojan emails.

Unless you are doing something funny with Zimbra, MySQL current shouldn't be an issue as there is no public exposure.

Although Postfix isn't current, I don't think any of those releases included security updates, I think they are just normal feature/bug fix updates. I have a lot of confidence in Postfix because it's security track record speaks for itself.

Apache/PHP/A-Spell seems lower risk because of the very limited nature of what you are *supposed* to be doing with that.

Just because there is a vulnerability in a package doesn't mean that you are exposed. It really depends on how the package is being used. So, for example, even though PHP is not current and there are security updates for PHP, I don't think that Zimbra is affected by those because of how it is used.
Reply With Quote
  #12 (permalink)  
Old 12-24-2006, 12:12 PM
Moderator
 
Posts: 1,209
Default Not Every Component Needs To Be at The Latest Version

It makes sense to me have ClamAV and SpamAssassin be quickly updated within Zimbra when ClamAV and SA are updated themselves. These packages directly impact the end user experience, and with the overwhelming majority of email traffic comprising spam, bots and viruses, these two packages stand out as ones Zimbra ought to be updating ASAP, IMHO.

Re Apache, Cyrus, Postfix and MySQL, I believe we should get security updates ASAP, but we don't need version updates unless there is a major functionality improvement (anvil in postfix comes to mind as worthy of justifying a version upgrade).

Since Zimbra insists on installing its own version of components normally supplied by a distro, Zimba to me is kind of like a mini-distro. Consequently, I think Zimbra have a responsibility to keep their "distro" as secure as possible, just as Fedore, SuSE, etc. keep the components of their distro up to date with security updates on a timely basis.

All the best,
Mark
Reply With Quote
  #13 (permalink)  
Old 03-04-2007, 11:41 AM
Project Contributor
 
Posts: 203
Default I opened a bug (RFE) for this...

http://bugzilla.zimbra.com/show_bug.cgi?id=15137

Please vote if you want to see out-of-cycle updates for clamav/spamassassin/etc.
Reply With Quote
  #14 (permalink)  
Old 03-05-2007, 08:12 AM
Special Member
 
Posts: 149
Default

As a paying customer, who's liable for not providing a security update ? If it's provided, but not applied, the responsibility lies on th end user. If the vendor does not provide one in a reasonable time, then won't they be liable ?

These packages should be updated as soon as a security fix is made available, or they should left out for the user to update provided the means to do so is supported.

My .02...
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.