Search found 226 matches

by barrydegraaff
Wed Aug 23, 2023 8:10 am
Forum: Administrators
Topic: Zimbra Security Update
Replies: 69
Views: 619641

Re: Zimbra Security Update

For Zimbra 8 OSE you can update using yum/apt update. For other versions you can rebuild from source and we will release the mitigation steps later.
by barrydegraaff
Wed Aug 23, 2023 6:12 am
Forum: Administrators
Topic: Zimbra Security Update
Replies: 69
Views: 619641

Zimbra Security Update

A one-click security vulnerability in all versions of Zimbra Collaboration Suite has been discovered that could allow an unauthenticated attacker to gain access to a Zimbra account. To fix this vulnerability install the latest Zimbra patch (by using apt or yum), the vulnerability is fixed in: - Daff...
by barrydegraaff
Tue Aug 22, 2023 3:57 pm
Forum: Administrators
Topic: clamAV CVE-2023-20032
Replies: 45
Views: 29342

Re: clamAV CVE-2023-20032

halfgaar wrote: Fri Aug 18, 2023 2:14 pm At this point, clamav is becoming more of a problem than me actually getting virussus.
Unofficially: this is how I felt about ClamAV for a long time, if you want AV that catches new threats, the better way is end-point protection.
by barrydegraaff
Thu Jun 08, 2023 1:35 pm
Forum: Installation and Upgrade
Topic: 8.8.15 Patch 40 GA Release
Replies: 61
Views: 48509

Re: 8.8.15 Patch 40 GA Release

I have filed ZBUG-3457 Improve error handling on bad uuencoded inline images
by barrydegraaff
Thu Jun 08, 2023 9:56 am
Forum: Installation and Upgrade
Topic: 8.8.15 Patch 40 GA Release
Replies: 61
Views: 48509

Re: 8.8.15 Patch 40 GA Release

% zmcontrol -v Release 8.8.15_GA_3953.RHEL8_64_20200629025823 RHEL8_64 NETWORK edition, Patch 8.8.15_P40. I believe this is a problem for us now. It has to do with forwarding an inline image that was uuencoded. An example of this would be from a company like Marriott Hotels when they send the state...
by barrydegraaff
Tue Jun 06, 2023 3:35 pm
Forum: Installation and Upgrade
Topic: 8.8.15 Patch 40 GA Release
Replies: 61
Views: 48509

Re: 8.8.15 Patch 40 GA Release

Here is what we see in the logs: 2023-05-31 22:47:55,838 ERROR [qtp439928219-42:https://mail.example.com/] [] webclient - Unable to get domain config com.zimbra.common.service.ServiceException: error while proxying request to target server: Service Unavailable If you can try and re-apply the update...
by barrydegraaff
Thu May 11, 2023 7:59 am
Forum: Community News
Topic: Zimbra Forums upgrade news
Replies: 11
Views: 23791

Re: Zimbra Forums upgrade news

Hello All, For fixing the security policy violation we need to know exactly what steps you took so we can reproduce the issue. Please provide us the reproduction steps with a clean browser, meaning clear all cookies. Cookies from zimbra.com can affect the policy at the wiki. In case you can not repr...
by barrydegraaff
Wed Apr 05, 2023 12:37 pm
Forum: Installation and Upgrade
Topic: Zimbra 8.8.15 Patch 39
Replies: 16
Views: 5902

Re: Zimbra 8.8.15 Patch 39

Thanks for reporting this issue, the engineering team is investigating as it has been reported by multiple users.
by barrydegraaff
Tue Apr 04, 2023 11:08 am
Forum: Administrators
Topic: Down for maintenence, administrators see /opt/zimbra/status.txt
Replies: 62
Views: 85943

Re: Down for maintenence, administrators see /opt/zimbra/status.txt

Anyone that is unsure if their Zimbra system is compromised can look at these 10 steps to get some more insights, https://blog.zimbra.com/2023/04/10-step ... ompromise/ and https://wiki.zimbra.com/wiki/10_steps_t ... compromise