Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
 
Go Back   Zimbra - Forums > General Zimbra > Announcements

Welcome to the Zimbra - Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 09-29-2008, 02:06 PM
Zimbra-Yahoo Consultant
 
Posts: 5,608
Exclamation Security Advisory: Zimbra Desktop

Severity:
Moderate

Impact:
Zimbra Desktop users who use Yahoo! Mail within Zimbra Desktop.

Versions Affected:
Zimbra Desktop Beta 3 and earlier (Zimbra Collaboration Suite or ZCS is not affected)

Summary:
The current (and previous) versions of Zimbra Desktop transmit credentials unencrypted to Yahoo! IMAP servers if using a Yahoo Premium Account. This may allow a malicious user to discover your credentials if using the appropriate software, under certain conditions.

The upcoming release of Yahoo! Zimbra Desktop will use cookie based authentication when communicating with Yahoo! Mail IMAP service.

A cookie is generated over a secure channel (SSL), and then used for authentication with various Yahoo! services including IMAP. The type of cookies used by the Desktop client has a scope limited to mail and address book services, has a short validity window of 1 hour, and can be revoked by server.

No Yahoo! credentials will be sent over unencrypted connections in the upcoming release of Zimbra Desktop.

Action:
Most Zimbra Desktop users are unaffected. Only those connecting to Yahoo! Mail via Zimbra Desktop have the potential to be affected. Zimbra will send out an auto update when we release Beta 4 of Zimbra Desktop. Users who are uncomfortable with transmitting their credentials in clear text should follow the wiki article below to uninstall, and wait for the next release.


Uninstalling Zimbra Desktop

How to Report A Security Issue
Reply With Quote
Reply


Thread Tools
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

Zimbrablog.com




 

Search Engine Optimization by vBSEO 3.1.0