Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "8.7.6"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.7"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.9"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.10"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-NA"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p1"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p10"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p11"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p12"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p13"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p14"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p15"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p2"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p3"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p4"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p5"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p6"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p7"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p8"
},
{
"introduced": "0"
},
{
"last_affected": "8.7.11-p9"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.3"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.4"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.6"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.7"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.8-NA"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.8-p1"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.8-p3"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.8-p4"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.8-p7"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.9-NA"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.9-p1"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.9-p10"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.9-p3"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.10-NA"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.10-p8"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.11-NA"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.11-p3"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.11-p4"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.11-p5"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.12-NA"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.12-p3"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.12-p4"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.15-NA"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.15-p11"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.15-p26"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.15-p3"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.15-p30"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.15-p31"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.15-p32"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.15-p33"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.15-p34"
},
{
"introduced": "0"
},
{
"last_affected": "8.8.15-p5"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-p0"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-p19"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-p23"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-p25"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-p26"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-p27"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-p4"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-p7"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-p7\\.1"
}
]
}