==================================================================== CERT-Renater Note d'Information No. 2020/VULN325 _____________________________________________________________________ DATE : 09/06/2020 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Zimbra versions prior to 9.0.0 Patch 3, 8.8.15 Patch 10. ===================================================================== https://blog.zimbra.com/2020/06/new-zimbra-patches-9-0-0-patch-3-and-8-8-15-patch-10/ _____________________________________________________________________ NEW Zimbra Patches: 9.0.0 Patch 3 + 8.8.15 Patch 10 By Urvi Mehta on June 3, 2020 in Product News, Product Updates, Zimbra Server Hello Zimbra Friends, Customers & Partners, Zimbra 9.0.0 “Kepler” Patch 3 and 8.8.15 “James Prescott Joule” Patch 10 are here. For Zimbra 8.8.8 and above, you don’t need to download any patch builds. The patch packages can be installed using Linux package management commands. Please refer to the respective release notes for patch installation on Red Hat and Ubuntu platforms. Note: Installing a zimbra-patch package only updates the Zimbra core packages. RHEL (Red Hat Enterprise Linux) 8 support (Beta) We are nearing the end of our extensive QA cycle for this major upgrade. Watch for the GA announcement in an upcoming patch release. Zimbra 9.0.0 “Kepler” Patch 3 Patch 3 is here for the Zimbra 9.0.0 “Kepler” GA release, and it includes Security Fixes, What’s New, Fixed Issues, and Known Issues as listed in the release notes. Security Fixes Summary CVE-ID CVSS Score Zimbra Rating Fix Patch Version Unrestricted Upload of File with Dangerous Type CVE-2020-12846 4.3 Minor 9.0.0 P3 Patch Installation Please refer to the release notes for Zimbra 9.0.0 Patch 3 installation on Red Hat and Ubuntu platforms. Zimbra 8.8.15 “James Prescott Joule” Patch 10 Patch 10 is here for the Zimbra 8.8.15 “James Prescott Joule” GA release, and it includes Security Fixes, What’s New, Fixed Issues, and Known Issues as listed in the release notes. Security Fixes Summary CVE-ID CVSS Score Zimbra Rating Fix Patch Version Unrestricted Upload of File with Dangerous Type CVE-2020-12846 4.3 Minor 8.8.15 P10 Patch Installation Please refer to the release notes for Zimbra 8.8.15 Patch 10 installation on Red Hat and Ubuntu platforms. Many thanks, Your Zimbra Team ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================