VMWare Zimbra Mailer Release 8.6.0.GA Replay Attack

Discussion in 'News Aggregator' started by Packet Storm, 2 Feb 2016.

  1. Packet Storm

    Packet Storm Guest

    VMWare Zimbra Mailer Release 8.6.0.GA, latest patch and prior versions with DKIM implementation are vulnerable to longterm Mail Replay attacks. If the expiration header is not set, the signature never expires. This means, that the e-mail, perhaps caught while performing a man in the middle attack, can be replayed years after catching it.

    Continue reading...
     

Share This Page

Loading...