CVE-2022-37393
16.08.2022, 20:15
Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.Enginsight
Vendor | Product | Version |
---|---|---|
zimbra | collaboration | 8.7.6 |
zimbra | collaboration | 8.7.7 |
zimbra | collaboration | 8.7.9 |
zimbra | collaboration | 8.7.10 |
zimbra | collaboration | 8.7.11 |
zimbra | collaboration | 8.7.11:p1 |
zimbra | collaboration | 8.7.11:p10 |
zimbra | collaboration | 8.7.11:p11 |
zimbra | collaboration | 8.7.11:p12 |
zimbra | collaboration | 8.7.11:p13 |
zimbra | collaboration | 8.7.11:p14 |
zimbra | collaboration | 8.7.11:p15 |
zimbra | collaboration | 8.7.11:p2 |
zimbra | collaboration | 8.7.11:p3 |
zimbra | collaboration | 8.7.11:p4 |
zimbra | collaboration | 8.7.11:p5 |
zimbra | collaboration | 8.7.11:p6 |
zimbra | collaboration | 8.7.11:p7 |
zimbra | collaboration | 8.7.11:p8 |
zimbra | collaboration | 8.7.11:p9 |
zimbra | collaboration | 8.8.0:beta1 |
zimbra | collaboration | 8.8.2 |
zimbra | collaboration | 8.8.3 |
zimbra | collaboration | 8.8.4 |
zimbra | collaboration | 8.8.6 |
zimbra | collaboration | 8.8.7 |
zimbra | collaboration | 8.8.8 |
zimbra | collaboration | 8.8.8:p1 |
zimbra | collaboration | 8.8.8:p3 |
zimbra | collaboration | 8.8.8:p4 |
zimbra | collaboration | 8.8.8:p7 |
zimbra | collaboration | 8.8.9 |
zimbra | collaboration | 8.8.9:p1 |
zimbra | collaboration | 8.8.9:p10 |
zimbra | collaboration | 8.8.9:p3 |
zimbra | collaboration | 8.8.10 |
zimbra | collaboration | 8.8.10:p8 |
zimbra | collaboration | 8.8.11 |
zimbra | collaboration | 8.8.11:p3 |
zimbra | collaboration | 8.8.11:p4 |
zimbra | collaboration | 8.8.11:p5 |
zimbra | collaboration | 8.8.12 |
zimbra | collaboration | 8.8.12:p3 |
zimbra | collaboration | 8.8.12:p4 |
zimbra | collaboration | 8.8.15 |
zimbra | collaboration | 8.8.15:p11 |
zimbra | collaboration | 8.8.15:p26 |
zimbra | collaboration | 8.8.15:p3 |
zimbra | collaboration | 8.8.15:p30 |
zimbra | collaboration | 8.8.15:p31 |
zimbra | collaboration | 8.8.15:p32 |
zimbra | collaboration | 8.8.15:p33 |
zimbra | collaboration | 8.8.15:p34 |
zimbra | collaboration | 8.8.15:p5 |
zimbra | collaboration | 9.0.0:p0 |
zimbra | collaboration | 9.0.0:p19 |
zimbra | collaboration | 9.0.0:p23 |
zimbra | collaboration | 9.0.0:p25 |
zimbra | collaboration | 9.0.0:p26 |
zimbra | collaboration | 9.0.0:p27 |
zimbra | collaboration | 9.0.0:p4 |
zimbra | collaboration | 9.0.0:p7 |
zimbra | collaboration | 9.0.0:p7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References