Archive | Security & Privacy

Zimbra Collaboration Updates (8.0.9 & 8.5.1)

Yesterday, Zimbra released updates to Zimbra Collaboration, both the 8.0.x and 8.5.x trees. Security These updates address the OpenSSL security advisory dated October 15 and provide a partial fix for POODLE (due to the need for both client and server changes). Zimbra Collaboration 8.0.9 and 8.5.1 update the OpenSSL libraries for nginx, OpenLDAP and Postfix […]

Continue Reading

POODLE and SSLv3

This week has brought about the latest security vulnerability. Google’s Thai Duong, Krzysztof Kotowicz, and Bodo Möller made the vulnerability — POODLE (Padding Oracle On Downgraded Legacy Encryption) — public on Tuesday, October 14, 2014. POODLE is a padding oracle attack affecting Secure Sockets Layer (SSL) version 3 and in particular, CBC-mode ciphers. This vulnerability […]

Continue Reading

The Shellshock Flaw

***Security Alert*** [Update 2 | September 30, 2014, 9:10am CST] Apple has released at update. [Update 1 | September 26, 2014, 11:40am CST] Red Hat has released a full patch. [Original Post | September 25, 2014, 1:45pm CST] Zimbra is aware and has been closely monitoring the developments of the Shellshock vulnerability. At this time, […]

Continue Reading

Forums.zimbra.com Incident and Resolution

On Sunday, August 31, Zimbra’s information security and technology team noticed unusual activity on the Zimbra vBulletin forum on Zimbra.com. We immediately took steps to limit the impact of the malicious activity. This did not affect customer, partner or employee data. This was not a breach of Zimbra products. Immediate action was taken to ensure […]

Continue Reading

Microsoft Ruling a Setback to Data Privacy?

For any organization that relies on cloud-based email, there is an important legal decision that may affect your company’s data privacy. In the most recent round of judgment against Microsoft, there are noteworthy remarks from US District Judge Loretta Preska and lawyers for the US Justice Department. “It is a question of control, not a […]

Continue Reading

Security Advisory on CCS Injection Vulnerability

On June 5, 2014 the OpenSSL project released a security advisory. CVE-2014-0224 can allow for a man-in-the-middle (MITM) attack to be carried out between a vulnerable client and vulnerable server. According to OpenSSL, an attacker using a carefully crafted handshake can force the use of weak keying material in OpenSSL SSL/TLS clients and servers. This can be exploited […]

Continue Reading

Copyright © 2022 Zimbra, Inc. All rights reserved.

All information contained in this blog is intended for informational purposes only. Synacor, Inc. is not responsible or liable in any manner for the use or misuse of any technical content provided herein. No specific or implied warranty is provided in association with the information or application of the information provided herein, including, but not limited to, use, misuse or distribution of such information by any user. The user assumes any and all risk pertaining to the use or distribution in any form of any subject matter contained in this blog.

Legal Information | Privacy Policy | Do Not Sell My Personal Information | CCPA Disclosures