Zimbra Releases/8.8.7: Difference between revisions
No edit summary |
m (→Security Fixes) |
||
(5 intermediate revisions by one other user not shown) | |||
Line 10: | Line 10: | ||
=Zimbra Collaboration 8.8.7 GA Release= | =Zimbra Collaboration 8.8.7 GA Release= | ||
<div class="col-md-9"> | <div class="col-md-9"> | ||
Check out the '''"[[#security|Security Fixes]]"''', '''"[[#fixed|Fixed Issues]]"''' and '''"[[#known|Known Issues]]"''' for this version of Zimbra Collaboration. We've also added a '''"[[#zextras|ZeXtras Suite Changelog]]"''' and '''"[[#compatibility|Compatibility]]"''' section with useful information. As always, you’re encouraged to tell us what you think in the '''[https://forums.zimbra.org/ Forum]''', or open a support ticket. | |||
Check out the '''"[[#fixed|Fixed Issues]]"''' | |||
<div class="alert alert-dark fade in"> <p>'''NOTE: If you are upgrading and/or migrating from an older version of Zimbra to Zimbra 8.8 Production Ready, please read [https://wiki.zimbra.com/wiki/Zimbra_Next_Generation_Modules/Things_To_Know_Before_Upgrading "Things to Know Before Upgrading"] and [https://wiki.zimbra.com/wiki/Zimbra_Next_Generation_Modules/First_Steps_with_the_Zimbra_NG_Modules "First Steps with the Zimbra NG Modules"] for critical information before you upgrade.'''</p></div> | <div class="alert alert-dark fade in"> <p>'''NOTE: If you are upgrading and/or migrating from an older version of Zimbra to Zimbra 8.8 Production Ready, please read [https://wiki.zimbra.com/wiki/Zimbra_Next_Generation_Modules/Things_To_Know_Before_Upgrading "Things to Know Before Upgrading"] and [https://wiki.zimbra.com/wiki/Zimbra_Next_Generation_Modules/First_Steps_with_the_Zimbra_NG_Modules "First Steps with the Zimbra NG Modules"] for critical information before you upgrade.'''</p></div> | ||
Line 17: | Line 16: | ||
<br /> | <br /> | ||
=Security Fixes= | |||
<div id="security"></div> | |||
Information about security fixes, security response policy and vulnerability rating classification are listed below. See the [https://wiki.zimbra.com/wiki/Zimbra_Security_Response_Policy Zimbra Security Response Policy] and the [https://wiki.zimbra.com/wiki/Zimbra_Vulnerability_Rating_Classification Zimbra Vulnerability Rating] Classification information below for details. | |||
<table class="table table-striped table-condensed"> | |||
<tr> | |||
<th style="background-color: #f15922; width: 80px;"><span style="color: #ffffff;">Bug#</span></th> | |||
<th style="background-color: #f15922;"><span style="color: #ffffff;">Summary</span></th> | |||
<th style="background-color: #f15922;"><span style="color: #ffffff;"><strong>CVE-ID</strong></span></th> | |||
<th style="background-color: #f15922;"><span style="color: #ffffff;"><strong>CVSS<br>Score</strong></span></th> | |||
<th style="text-align: center; background-color: #f15922;"><span style="color: #ffffff;"><strong>Zimbra<br>Rating</strong></span></th> | |||
<th style="text-align: center; background-color: #f15922;"><span style="color: #ffffff;">Fix Release or <br>Patch Version</span></th> | |||
</tr> | |||
<tr> | |||
<td class="col-md-1">[https://bugzilla.zimbra.com/show_bug.cgi?id=108786 108786]</td> | |||
<td> Persistent XSS [https://cwe.mitre.org/data/definitions/79.html CWE-79]</td> | |||
<td> CVE-2018-6882</td> | |||
<td>[https://nvd.nist.gov/cvss.cfm?calculator&version=2&vector=(AV:N/AC:H/Au:N/C:N/I:P/A:N) 4.3]</td> | |||
<td style="text-align: center;">Minor</td> | |||
<td style="text-align: center;">8.7.11 Patch 1<br /> 8.8.7</td> | |||
</tr> | |||
<tr> | |||
<td class="col-md-1">[https://bugzilla.zimbra.com/show_bug.cgi?id=108709 108709]</td> | |||
<td> Mailsploit</td> | |||
<td> - </td> | |||
<td> - </td> | |||
<td style="text-align: center;"> - </td> | |||
<td style="text-align: center;">8.7.11 Patch 1 <br /> 8.8.7</td> | |||
</tr> | |||
</table> | |||
=Software changes= | |||
<table class="table table-striped table-condensed"> | <table class="table table-striped table-condensed"> | ||
<tr> | <tr> | ||
Line 22: | Line 52: | ||
</tr> | </tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=107793 107793] </td><td class="col-md-10"> zmmigrateattrs throws exceptions</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=107793 107793] </td><td class="col-md-10"> zmmigrateattrs throws exceptions</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=107788 107788] </td><td class="col-md-10"> Value of zimbraLastLogonTimeStamp is stored in LDAP even after migration</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=107788 107788] </td><td class="col-md-10"> Value of zimbraLastLogonTimeStamp is stored in LDAP even after migration</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=107796 107796] </td><td class="col-md-10"> zmrestoreoffline -h hangs if mailboxd is running</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=107796 107796] </td><td class="col-md-10"> zmrestoreoffline -h hangs if mailboxd is running</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108874 108874] </td><td class="col-md-10"> Change stack trace log level to debug for getItem failure</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108874 108874] </td><td class="col-md-10"> Change stack trace log level to debug for getItem failure</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108875 108875] </td><td class="col-md-10"> Outlook is not quitting by clicking on ""Exit Outlook & Upgrade"" button</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108875 108875] </td><td class="col-md-10"> Outlook is not quitting by clicking on ""Exit Outlook & Upgrade"" button</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108219 108219] </td><td class="col-md-10"> Error handling for the sieve filter match operation was changed in ZCS 8.7.11</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108219 108219] </td><td class="col-md-10"> Error handling for the sieve filter match operation was changed in ZCS 8.7.11</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108237 108237] </td><td class="col-md-10"> Error handling for the sieve filter matchCondition used for replaceheader and deleteheader</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108237 108237] </td><td class="col-md-10"> Error handling for the sieve filter matchCondition used for replaceheader and deleteheader</td></tr> | ||
Line 36: | Line 64: | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108613 108613] </td><td class="col-md-10"> Organizer see attendee status as Tentative instead of Accepted for proposed new time in invite by attendee</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108613 108613] </td><td class="col-md-10"> Organizer see attendee status as Tentative instead of Accepted for proposed new time in invite by attendee</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108692 108692] </td><td class="col-md-10"> Unable to close time frame in Calendar with Month view</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108692 108692] </td><td class="col-md-10"> Unable to close time frame in Calendar with Month view</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=107700 107700] </td><td class="col-md-10"> Some Spaces removed in RFC 2047 encoded subject</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=107700 107700] </td><td class="col-md-10"> Some Spaces removed in RFC 2047 encoded subject</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108879 108879] </td><td class="col-md-10"> IMAPD (remote IMAP) returns no more than 1000 messages for UID SEARCH</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108879 108879] </td><td class="col-md-10"> IMAPD (remote IMAP) returns no more than 1000 messages for UID SEARCH</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108709 108709] </td><td class="col-md-10"> ZWC affected by Mailsploit due to default zimbraPrefShortEmailAddress TRUE</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108709 108709] </td><td class="col-md-10"> ZWC affected by Mailsploit due to default zimbraPrefShortEmailAddress TRUE</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108777 108777] </td><td class="col-md-10"> Calendar read only on MacOS High Sierra with Exchange Account</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108777 108777] </td><td class="col-md-10"> Calendar read only on MacOS High Sierra with Exchange Account</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108414 108414] </td><td class="col-md-10"> NPE in ImapListener causes mailbox lock to not be released</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108414 108414] </td><td class="col-md-10"> NPE in ImapListener causes mailbox lock to not be released</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108786 108786] </td><td class="col-md-10"> Persistent XSS - content-location [CWE-79]</td></tr> | <tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108786 108786] </td><td class="col-md-10"> Persistent XSS - content-location [CWE-79]</td></tr> | ||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108882 108882] </td><td class="col-md-10"> Outlook 2016 + August 2017 Update: Exception seen during installation</td></tr> | |||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108476 108476] </td><td class="col-md-10"> Update the Installer to allow Profile creation on Outlook 2016 click to run versions.</td></tr> | |||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108883 108883] </td><td class="col-md-10"> ZCO Problem messages cause SYNCMAIN Thread crash and sync to fail</td></tr> | |||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=64970 64970] </td><td class="col-md-10"> Unable to send email from Zimbra to Exchange using mixed profile (Zimbra primary + Exchange secondary)</td></tr> | |||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108884 108884] </td><td class="col-md-10"> Admin console contact "Notes" field is not gal-synced to ZCO contact Notes "field" (but ZAC "Description" field IS)</td></tr> | |||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108885 108885] </td><td class="col-md-10"> L10N ZCO Support for Catalan</td></tr> | |||
<tr><td class="col-md-1"> [https://bugzilla.zimbra.com/show_bug.cgi?id=108886 108886] </td><td class="col-md-10"> L10N ZCO Support for Norwegian</td></tr> | |||
</table> | </table> | ||
Line 96: | Line 126: | ||
</table> | </table> | ||
=Quick note: Compatibility= | |||
<div id="compatibility"></div> | |||
Zimbra Drive is compatible with: | |||
* [https://nextcloud.com/changelog NextCloud] versions 9, 10, 11, and 12 only | |||
* [https://owncloud.com ownCloud] versions 9.0, 9.1, and 10 only | |||
=Quick note: Open Source repo= | |||
Downloading and building our Zimbra Code? Keep reading... Starting ZCS 8.7.6 and above we have new steps to download, build and see our code via Github: | Downloading and building our Zimbra Code? Keep reading... Starting ZCS 8.7.6 and above we have new steps to download, build and see our code via Github: | ||
*https://github.com/Zimbra/zm-build | *https://github.com/Zimbra/zm-build |
Latest revision as of 23:50, 9 May 2018
Zimbra Collaboration 8.8.7 GA Release
Check out the "Security Fixes", "Fixed Issues" and "Known Issues" for this version of Zimbra Collaboration. We've also added a "ZeXtras Suite Changelog" and "Compatibility" section with useful information. As always, you’re encouraged to tell us what you think in the Forum, or open a support ticket.
NOTE: If you are upgrading and/or migrating from an older version of Zimbra to Zimbra 8.8 Production Ready, please read "Things to Know Before Upgrading" and "First Steps with the Zimbra NG Modules" for critical information before you upgrade.
Security Fixes
Information about security fixes, security response policy and vulnerability rating classification are listed below. See the Zimbra Security Response Policy and the Zimbra Vulnerability Rating Classification information below for details.
Bug# | Summary | CVE-ID | CVSS Score |
Zimbra Rating |
Fix Release or Patch Version |
---|---|---|---|---|---|
108786 | Persistent XSS CWE-79 | CVE-2018-6882 | 4.3 | Minor | 8.7.11 Patch 1 8.8.7 |
108709 | Mailsploit | - | - | - | 8.7.11 Patch 1 8.8.7 |
Software changes
|
|
---|---|
107793 | zmmigrateattrs throws exceptions |
107788 | Value of zimbraLastLogonTimeStamp is stored in LDAP even after migration |
107796 | zmrestoreoffline -h hangs if mailboxd is running |
108874 | Change stack trace log level to debug for getItem failure |
108875 | Outlook is not quitting by clicking on ""Exit Outlook & Upgrade"" button |
108219 | Error handling for the sieve filter match operation was changed in ZCS 8.7.11 |
108237 | Error handling for the sieve filter matchCondition used for replaceheader and deleteheader |
108876 | Alert not displayed for expired license with remote IMAP server |
100973 | MacOutlook: Meeting response received by Outlook from DL users does not get updated in Scheduling tab |
108877 | "CreateZimbraProfile.exe" blank window flashing in ZCO installation |
108878 | Outlook crashes when selecting user from outside domain |
108613 | Organizer see attendee status as Tentative instead of Accepted for proposed new time in invite by attendee |
108692 | Unable to close time frame in Calendar with Month view |
107700 | Some Spaces removed in RFC 2047 encoded subject |
108879 | IMAPD (remote IMAP) returns no more than 1000 messages for UID SEARCH |
108709 | ZWC affected by Mailsploit due to default zimbraPrefShortEmailAddress TRUE |
108777 | Calendar read only on MacOS High Sierra with Exchange Account |
108414 | NPE in ImapListener causes mailbox lock to not be released |
108786 | Persistent XSS - content-location [CWE-79] |
108882 | Outlook 2016 + August 2017 Update: Exception seen during installation |
108476 | Update the Installer to allow Profile creation on Outlook 2016 click to run versions. |
108883 | ZCO Problem messages cause SYNCMAIN Thread crash and sync to fail |
64970 | Unable to send email from Zimbra to Exchange using mixed profile (Zimbra primary + Exchange secondary) |
108884 | Admin console contact "Notes" field is not gal-synced to ZCO contact Notes "field" (but ZAC "Description" field IS) |
108885 | L10N ZCO Support for Catalan |
108886 | L10N ZCO Support for Norwegian |
|
|
---|---|
108805 | ZCS886 has the wrong admin guide |
|
|
---|---|
Zimbra Chat:
| |
Zimbra Drive:
| |
NG Modules:
Backup NG
Mobile NG
HSM NG
|
Quick note: Compatibility
Zimbra Drive is compatible with:
Quick note: Open Source repo
Downloading and building our Zimbra Code? Keep reading... Starting ZCS 8.7.6 and above we have new steps to download, build and see our code via Github:
Try Zimbra
Try now Zimbra Collaboration without any cost with the 60-day free Trial.
Get it now »
Want to get involved?
You can contribute in the Community, in the Wiki, in the Code, or developing Zimlets.
Find out more. »
Other Help Resources
Visit the User Help Page »
Visit the Official Forums »
Zimbra Documentation Page »
Looking for a Video?
Visit our YouTube Channel to keep posted about Webinars, technology news, Product overviews and more.
Go to the YouTube Channel »