Quantcast
Channel: Zimbra Forums
Viewing all articles
Browse latest Browse all 1130

Administrators • Re: New CPIO vulnerability (CVE-2023-7216). Zimbra affected?

$
0
0
Looks very similar indeed, this could trick amavis (using cpio) to write files into /opt/zimbra/jetty/webapps/zimbra/public, which contains executable code.

This was initially fixed by installing pax, and later by avoiding cpio altogether.

But the real underlying issue of this –and several other Zimbra vulnerabilities– is that the whole of /opt/zimbra/jetty/webapps is writable for the zimbra user. Hopefully this will be addresses in the future.

Statistics: Posted by ghen — Tue Feb 13, 2024 3:23 pm



Viewing all articles
Browse latest Browse all 1130

Trending Articles