Executive brief
A vulnerability in Zimbra Collaboration Suite allows authenticated users to crash the mailbox service. This can lead to a total loss of email availability for users on the affected server, disrupting business communications and operations.
Technical details
This unspecified vulnerability (internally tracked as bug 102029) exists in Zimbra Collaboration Suite versions prior to 8.6.0 Patch 7. The flaw allows a remote authenticated user to trigger a denial of service condition by causing the 'mailboxd' process to shut down. While the exact technical vector is not disclosed in the advisory, it is classified as a P1/blocker bug by the vendor due to its impact on service availability. The issue is resolved in Zimbra Collaboration 8.6.0 Patch 7.
Affected products
- Zimbra Zimbra Collaboration Suite before 8.6.0 Patch 7
Timeline
- 2016-06-28: patched: Zimbra Collaboration 8.6.0 Patch 7 released
- 2017-01-18: disclosed: NVD publication date