Junglewise Threat Intelligence

CVE-2016-3414: Zimbra Collaboration denial of service in mailboxd

CVE-2016-3414 · Severity: medium · CVSS 6.5 · Published 2017-01-18

Technologies: Synacor Zimbra Collaboration Suite, Zimbra Collaboration Suite. Vendors: Synacor, Zimbra.

Executive brief

A vulnerability in Zimbra Collaboration Suite allows authenticated users to crash the mailbox service. This can lead to a total loss of email availability for users on the affected server, disrupting business communications and operations.

Technical details

This unspecified vulnerability (internally tracked as bug 102029) exists in Zimbra Collaboration Suite versions prior to 8.6.0 Patch 7. The flaw allows a remote authenticated user to trigger a denial of service condition by causing the 'mailboxd' process to shut down. While the exact technical vector is not disclosed in the advisory, it is classified as a P1/blocker bug by the vendor due to its impact on service availability. The issue is resolved in Zimbra Collaboration 8.6.0 Patch 7.

Affected products

  • Zimbra Zimbra Collaboration Suite before 8.6.0 Patch 7

Timeline

  • 2016-06-28: patched: Zimbra Collaboration 8.6.0 Patch 7 released
  • 2017-01-18: disclosed: NVD publication date

References

Related threats