zimbra-logoLast week, Zimbra issued patch releases for Zimbra Collaboration 8.x and 7.x, resolving two critical security vulnerabilities. It’s strongly recommend that any customer running the following versions of Zimbra Collaboration apply the patches:
8.0.5, 8.0.4, 8.0.3
7.2.5, 7.2.4, 7.2.3, 7.2.2
These issues are being tracked in Zimbra Bugzilla systems as the following:
Bug # 80338
Summary: Privilege Escalation via LFI
Affected Versions: 7.2.2 and 8.0.2 and all previous releases
Bug # 84547
Summary: Critical Security Vulnerability
Affected Versions: 7.2.5 and 8.0.5 and all previous releases
The official patch downloads and release notes can be found here: Network Edition Downloads: Enterprise Messaging and Collaboration Software by Zimbra or for Open Source Edition : Binary Archive for Open Source Editions
Please follow the release notes for installation instructions. Each patch release is a cumulative update, including any fixes from previous patch releases for that version.
More Details :

Bug 80338 (Feb 2013) is a Local File Inclusion vulnerability that leads to potential Privilege Escalation:

Bug 84547 is a newer Critical Security Vulnerability (Dec 2013) that has not had further details released (in order to protect other customers):

There is great urgency for getting this patched on your platform, as there is an exploit for Bug 80338 in the wild, discussed here:

And it has been used to install upload rogue Zimlets and bitcoin mining processes (and potentially others) on some customer systems. You can read about the clean-up steps for this here:

As noted, there are patches and upgrades available here:

Please let us know if further questions. Please upgrade or patch at first opportunity. Sorry for the difficulties on this.

I strongly recommend to upgrading all Zimbra version 7.x.x into 7.2.6 and 8.x.x into 8.0.6 if possible. If you can not perform an update in the near future, please go with the above update releases ( only need a few steps than upgrading all services). Based on experience, upgrading Zimbra 6.0.8 in SLES 11 SP1 64 bit into 8.0.6 are worked flawlessly with only a few library update (zlib library). I’ll be post the details later on next tutorial 😉

Leave a Reply

Your email address will not be published.