CVE-2025-53603

NameCVE-2025-53603
DescriptionIn Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1108798

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
sogo (PTS)bullseye (security), bullseye5.0.1-4+deb11u1vulnerable
bookworm5.8.0-1vulnerable
sid, trixie5.12.1-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sogosource(unstable)(unfixed)1108798

Notes

https://www.openwall.com/lists/oss-security/2025/07/02/3
https://github.com/Alinto/sope/pull/69

Search for package or bug name: Reporting problems