Archive | Security & Privacy

NEW! Patch Release: Compression support on S3 external volumes, Enabled Concurrent Socket Connection for OpenJDK & Other Enhancements

Patch Security Severity: Medium Deployment Risk: Medium This release focuses on essential security and improving user experience for the following editions Zimbra Daffodil 10.0.8 (Release Notes) Zimbra 9.0.0 Kepler Patch-40 (Release Notes) Patch updated on Apr 22 include the following in their respective releases What’s New Performance Enabled concurrent socket connection for OpenJDK External Storage […]

Continue Reading 0

Patch Release: Improved Language Support, Modern UI, Distribution Lists & Other Security Enhancements

Patch Security Severity: Low Deployment Risk: Medium This release focuses on improving user experience, enhancing group communication and essential security for the following editions Zimbra Daffodil 10.0.7 (Release Notes) Zimbra 9.0.0 Kepler Patch-39 (Release Notes) Patch updated on 28 Feb include the following in their respective releases What’s New Improved Language Support (Zimbra Daffodil) OnlyOffice […]

Continue Reading 0

How to implement (external LDAP) authentication in a Zimbra Java Extension

Frequent readers of the Zimbra blog will know that Zimbra can be extended/customized by using Zimlets. By creating your own Zimlets you can add functionality to the UI (front-end) and the Java back-end, allowing you to cater to specific customer needs. Zimlets can be enabled globally or per user (group) Details on this can be […]

Continue Reading 0

SMTP Smuggling in Zimbra Postfix a technical deepdive

E-mail providers like Microsoft Exchange Online and GMX allowed to pass <LF>.<CR><LF> sequence unfiltered from their outbound (sending mails) SMTP server to the inbound (receiving mails) SMTP server (postfix in our case). In the case of Postfix serving as an outbound/inbound (sending mails/receiving mails) server, it does not ignore the sequence ‘<LF>.<CR><LF>’; rather, it interprets […]

Continue Reading 0

Copyright © 2022 Zimbra, Inc. All rights reserved.

All information contained in this blog is intended for informational purposes only. Synacor, Inc. is not responsible or liable in any manner for the use or misuse of any technical content provided herein. No specific or implied warranty is provided in association with the information or application of the information provided herein, including, but not limited to, use, misuse or distribution of such information by any user. The user assumes any and all risk pertaining to the use or distribution in any form of any subject matter contained in this blog.

Legal Information | Privacy Policy | Do Not Sell My Personal Information | CCPA Disclosures