Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Summary
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. Also patched
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.