Patch 1 has been issued for 8.8.8 GA release that includes fixes as listed in the release notes.
Fixed Issues (Bugzilla query) |
|
---|---|
35115 | RFE: Handling multi-valued zimbraAuthLdapURL |
108928 | [Defanger] Specific message causing defanger to loop and cause high CPU load |
108929 | [Zimbra Chat] Multiple spaces getting trimmed from chat message |
108930 | [Zimbra Talk] “Incoming video call” dialog doesn’t disappear when call is disconnected by caller |
Security Fixes
Information about security fixes, security response policy and vulnerability rating classification are listed below. See the Zimbra Security Response Policy and the Zimbra Vulnerability Rating Classification information below for details.
Bug# | Summary | CVE-ID | CVSS Score |
Zimbra Rating |
Fix Release or Patch Version |
---|---|---|---|---|---|
97579 | login CSRF protection: ZWC login form does not use a csrf token [CWE-352] | CVE-2015-7610 | 5.8 | Major | 8.8.8 Patch1 |
Please refer to the release notes for 8.8.8 Patch 1 installation instructions.
Patch 2 has been issued for 8.7.11 GA release that includes fixes as listed in the release notes.
Fixed Issues (Bugzilla query) |
|
---|---|
35115 | RFE: Handling multi-valued zimbraAuthLdapURL |
107700 | Some Spaces removed in RFC 2047 encoded subject |
108928 | [Defanger] Specific message causing defanger to loop and cause high CPU load |
Security Fixes
Information about security fixes, security response policy and vulnerability rating classification are listed below. See Zimbra Security Response Policy and Zimbra Vulnerability Rating Classification information below for details.
Bug# | Summary | CVE-ID | CVSS Score |
Zimbra Rating |
Fix Release or Patch Version |
---|---|---|---|---|---|
97579 | login CSRF protection: ZWC login form does not use a csrf token [CWE-352] | CVE-2015-7610 | 5.8 | Major | 8.7.11 Patch2 |
Please refer to the release notes for 8.7.11 Patch 2 installation instructions.
How to Get the Patches?
8.8.8 Patch 1
For 8.8.8 Patch 1, you don’t need to download any patch builds. Instead, patch packages can be installed by using Linux package management commands.
Please refer to the release notes for 8.8.8 Patch 1 installation on Redhat and Ubuntu platforms.
8.7.11 Patch 2
For 8.7.11 Patch 2, you can download the patch from this link.
Hi!
After patch can’t install new entity of ZCS open source.
zimbra-networn-modules-ng depends error zombra-network-store not installable.
P.S.: Also, cant regist to forum: capcha dont work!
Please chek!
Hi – we have fixed the forums. If you are still having issues, please post in the forums for a quick response. Thanks!
After installation 8.8.8 patch1 I encountered the following problems:
-Android browser does not allow mobile view, can not display mails.
-Printing problem No Result Found display appears instead of the letter you want to print.