We have been working hard to deliver Patch 5 for the 8.6.0 release before the holidays. There are 32 bugs that are now resolved, including eight important Security bugs.
Download the Patch 5
Please do a full backup or snapshot before installing this Patch. You can download the patch and the md5 and the SHA 256 file here:
- Download the Patch for Network Edition and for Open Source Edition
Please, read the Full Release Notes here.
All Zimbra Collaboration 8.6.0 sites are recommended to install this patch. Patch 5 is cumulative with Patch 1, 2, 3, and 4, so only Patch 5 is required in case that you didn’t installed the previous ones.
Security Fixes
Information about security fixes, security response policy and vulnerability rating classification are listed below. See the Zimbra Security Response Policy and the Zimbra Vulnerability Rating Classification information below for details.
ZCS 8.6.0 Patch 5 includes the following security fixes.
Bug | Rating | CVSS Base Score | CVE-Number |
---|---|---|---|
Bug 101559 | Minor | 3.5 | CVE-2015-2249 |
Bug 101436 | Minor | 2.6 | CVE-2015-7609 |
Bug 101435 | Major | 6.4 | CVE-2015-7609 |
Bug 100133 | Minor | 3.5 | CVE-2015-2249 |
Bug 99914 | Minor | 3.5 | CVE-2015-2249 |
Bug 99854 | Minor | 3.5 | CVE-2015-2249 |
Bug 99236 | Minor | 4.3 | CVE-2012-5881 CVE-2012-5882 CVE-2012-5883 |
Bug 96973 | Minor | 4.3 | CVE-2015-2249 |
ZCS 8.6.0 Patch5 Bug Fixes
You might find useful the complete list of the fixed Bugs in this Patch 5 for Zimbra Collaboration 8.6.0.
Component |
Bug Number and Description |
Admin – Console |
|
Admin – Utilities |
|
Calendar – Server |
|
Calendar – Web Client |
|
Contacts – Web Client |
|
Install & Upgrade |
|
Mail – Server |
|
Mail – Web Client | |
Mobile – Zimbra Mobile Sync |
|
Other – Web Client | |
Standard HTML Client |
|
Before Installing the Patch
Before installing the patch, consider the following:
- Zimbra Collaboration patches can be found at https://www.zimbra.com/downloads/zimbra-collaboration
- Patches are delivered as a TGZ file and are cumulative.
- A full backup should be performed before any patch is applied. There is no automated roll-backmechanism.
- Zimlet patches can include removing existing Zimlets and redeploying the patched Zimlet.
- Only files or Zimlets associated with installed packages will be installed from the patch.
- Switch to user zimbra before using ZCS CLI commands.
Install the Patch
Read carefully the Release Notes, for this Patch 5.
Important! You cannot revert to the previous ZCS release after you upgrade to the patch.
Hi Jorge,
thanks for the patch. I have another issue wich is not mentioned in current patch. Sometime when user send email from iphone that consist an image in the email body, postfix recognize wrong file extension in the email body. for example:
“Koala.jpg;??x-apple-part-url=”781fefd5082b213036d392534fe08590@somedomain.com” recognize as .com extension (it will be issue when .com is blocked).
It appears that postfix not anticipate unknown character (example “) and change it to question mark (??)
Thanks
I was surprised lately how much the documentation has improved in the admin doc for each version. If I can’t find the info I’m looking for in there then I go straight to support as anything you search for is nearly alwayd for an older version so check the docs once more below https://www.zimbra.com/documentation/zimbra-collaboration
Hi,
where can I get more information about the security-fixes?
E.g. the issue 101435 marked as major is not public in bugzilla – and the CVE-candidate isn’t public either (yet)…
Or maybe it’s just that everybody is already in X-mas mo(o)d(e)…
In any case: Thanks for your hard work. A Merry Christmas and a Happy New Year to the Zimbra Team.
After installing patch 5 and set max users per cos in domain advanced settings the create new user action is broken, please provide a solution.
Thanks
Hi Alessandro,
You can find more information about this behaviour here – https://bugzilla.zimbra.com/show_bug.cgi?id=103122
We are currently investigating it, please add yourself to the bug and vote for it! If you are a customer, Fill a support ticket and link the bug number to the Support Case
Best regards
in zimbra GUI it showing service failed, but in CLI all services are running is any setting is there from GUI