Zimbra 8.8.15 Patch 38 Release please share experience

Ask questions about your setup or get help installing ZCS server (ZD section below).
bulletxt
Advanced member
Advanced member
Posts: 83
Joined: Sat Sep 13, 2014 1:08 am

Zimbra 8.8.15 Patch 38 Release please share experience

Post by bulletxt »

Hi
as topic suggests Zimbra has just release 8.8.15 Patch 38 release that fixes Clamav CVE stuff. Please share experience after upgrading
User avatar
JDunphy
Outstanding Member
Outstanding Member
Posts: 901
Joined: Fri Sep 12, 2014 11:18 pm
Location: Victoria, BC
ZCS/ZD Version: 9.0.0_P39 NETWORK Edition

Re: Zimbra 8.8.15 Patch 38 Release please share experience

Post by JDunphy »

Code: Select all

# Last metadata expiration check: 0:16:51 ago on Thu 02 Mar 2023 01:36:57 AM PST.
Dependencies resolved.
==============================================================================================================================================================================
 Package                                      Architecture                  Version                                              Repository                              Size
==============================================================================================================================================================================
Upgrading:
 zimbra-clamav                                x86_64                        0.105.2-1zimbra8.8b3.el8                             zimbra-8815-oss                        728 k
 zimbra-clamav-libs                           x86_64                        0.105.2-1zimbra8.8b3.el8                             zimbra-8815-oss                        3.8 M
 zimbra-mta-components                        x86_64                        1.0.19-1zimbra8.8b1.el8                              zimbra-8815-oss                        9.9 k
 zimbra-mta-patch                             x86_64                        8.8.15.1677488961.p38-1.r8                           zimbra-8815-oss                        116 k

Transaction Summary
==============================================================================================================================================================================
Upgrade  4 Packages
...
On RHEL8, no issues going from P37 to P38 for both OSS and Network versions.

Code: Select all

% zmcontrol -v
Release 8.8.15_GA_3953.RHEL8_64_20200629025823 RHEL8_64 NETWORK edition, Patch 8.8.15_P38.
% /opt/zimbra/common/sbin/clamd --help

                      Clam AntiVirus: Daemon 0.105.2
           By The ClamAV Team: https://www.clamav.net/about.html#credits
           (C) 2022 Cisco Systems, Inc.
....
....
freshclam pulled and reloaded db without issue. Sent test message without issue.
bulletxt
Advanced member
Advanced member
Posts: 83
Joined: Sat Sep 13, 2014 1:08 am

Re: Zimbra 8.8.15 Patch 38 Release please share experience

Post by bulletxt »

Zimbra is actually targeting the issue as Zimbra Rating "Low" https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P38 . Can someone give further information?
Klug
Ambassador
Ambassador
Posts: 2767
Joined: Mon Dec 16, 2013 11:35 am
Location: France - Drôme
ZCS/ZD Version: All of them
Contact:

Re: Zimbra 8.8.15 Patch 38 Release please share experience

Post by Klug »

They're not saying anything on it except "it's not that serious as there's no public exploit".
viewtopic.php?f=15&t=71693&start=20#p308303
User avatar
JDunphy
Outstanding Member
Outstanding Member
Posts: 901
Joined: Fri Sep 12, 2014 11:18 pm
Location: Victoria, BC
ZCS/ZD Version: 9.0.0_P39 NETWORK Edition

Re: Zimbra 8.8.15 Patch 38 Release please share experience

Post by JDunphy »

Cisco said it best on Feb 15:
https://www.helpnetsecurity.com/2023/02/17/cve-2023-20032-cve-2023-20009-cve-2023-20075/ wrote: “This vulnerability is due to a missing buffer size check that may result in a heap buffer overflow write. An attacker could exploit this vulnerability by submitting a crafted HFS+ partition file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the ClamAV scanning process, or else crash the process, resulting in a denial of service (DoS) condition,” Cisco explained.
IMHO, Zimbra's rating is too conservative. Amazons Linux Security Center rated this as 9.8 and critical in comparison.
Ref: https://alas.aws.amazon.com/cve/html/CV ... 20032.html
halfgaar
Advanced member
Advanced member
Posts: 173
Joined: Sat Sep 13, 2014 12:54 am
Location: Netherlands
ZCS/ZD Version: Ubuntu 18.04, 8.8.15_P43
Contact:

Re: Zimbra 8.8.15 Patch 38 Release please share experience

Post by halfgaar »

It was also pretty late. On my Debian systems, I already received this Feb 21st.
Consider seriously: because of the history of exploits: block Zimbra web interface with VPN, firewall or HTTP proxy.
bulletxt
Advanced member
Advanced member
Posts: 83
Joined: Sat Sep 13, 2014 1:08 am

Re: Zimbra 8.8.15 Patch 38 Release please share experience

Post by bulletxt »

https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P38

They just changed the rating to "CRITICAL"
User avatar
L. Mark Stone
Ambassador
Ambassador
Posts: 2802
Joined: Wed Oct 09, 2013 11:35 am
Location: Portland, Maine, US
ZCS/ZD Version: 10.0.7 Network Edition
Contact:

Re: Zimbra 8.8.15 Patch 38 Release please share experience

Post by L. Mark Stone »

JDunphy wrote: IMHO, Zimbra's rating is too conservative. Amazons Linux Security Center rated this as 9.8 and critical in comparison.
Ref: https://alas.aws.amazon.com/cve/html/CV ... 20032.html
Zimbra have changed the criticality in the Patch Release Notes to "Critical" FWIW.

IMHO all customers should be applying this patch forthwith.

Best regards to all,
Mark
___________________________________
L. Mark Stone
Mission Critical Email - Zimbra VAR/BSP/Training Partner https://www.missioncriticalemail.com/
AWS Certified Solutions Architect-Associate
agenis
Posts: 19
Joined: Mon Oct 28, 2019 8:04 pm

Re: Zimbra 8.8.15 Patch 38 Release please share experience

Post by agenis »

No problem whatsoever in Centos 7.
7224jobe
Outstanding Member
Outstanding Member
Posts: 284
Joined: Sat Sep 13, 2014 1:55 am
ZCS/ZD Version: 8.8.15_FOSS Patch38

Re: Zimbra 8.8.15 Patch 38 Release please share experience

Post by 7224jobe »

No problems with CentOS7 here, too.
We updated from 8.8.15 FOSS P31 to P38.
Post Reply