VMWare Zimbra Mailer Release 8.6.0.GA Replay Attack
Posted by deepcore on February 2, 2016 – 5:32 am
VMWare Zimbra Mailer Release 8.6.0.GA, latest patch and prior versions with DKIM implementation are vulnerable to longterm Mail Replay attacks. If the expiration header is not set, the signature never expires. This means, that the e-mail, perhaps caught while performing a man in the middle attack, can be replayed years after catching it.
Post a reply
You must be logged in to post a comment.