[DSA 5970-1] sope security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5970-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
July 31, 2025                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : sope
CVE ID         : CVE-2025-53603
Debian Bug     : 1108798

Stefan Buehler discovered a flaw in sope, the set of Objective-C
frameworks powering SOGo, which may result in denial of service via a
specially crafted POST request.

For the stable distribution (bookworm), this problem has been fixed in
version 5.8.0-1+deb12u1.

We recommend that you upgrade your sope packages.

For the detailed security status of sope please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/sope

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmiL2t9fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QYgg//WFQDHVM/B+fgBlKIi9SyT2Fji02AkYm3d71X2qRk+cZuuCmESsp7GcKh
6VVQdPTIfFP0V7WNfDHfhqXxpIb2oU3XKATF+096JjaeJSG05qh+9VYpsuourGb5
s6VkiwYe1u+8N2W50lKvoHJYlXSGjBK90OR0HrW4IP9LPP1pGxsF1y7boyYp7Rb3
xS+0m8bpzGxoH8lbztVoB7qhNyWveiagamuj6v37tPO0qPKS0nRSGDAw0bjbMOv2
YsVXZKzsQniLFrGV8jMEdpWY2cx+AGxskhM9rXC/Izht6IM1ZG8T0SzWzAQNzg/G
ZBmqbawGTfvwjVFL7pWuEjlrrI8K61Nhzbos6Qt3ECjPT8tJbN/o12EE8i6FeKKT
LKvPYT7DJJrXWP+eCckwqOUxRQ/zCetOGVzHhIakQIH4jSeOLq8FcYjqy8T51DLf
uYNRcbYp8pR6Dmb0/AGqMH2A7r0IdKC1vumK0Y6LPqLrmba7Tqom9ZqQcuUjsicN
xaeg4Dkd941E8v/g958KPEKY9Zl7ZuTd0oonC15UY2cM1U2w7eTkussjcNkEYBKl
hCAwEv+HESyKTHUrkUwVSWLneKVAK0VeZHnQXOXY+ypZZ1LveEWvQa8iU5GPoLim
3xfL20IjijeebxBnkgVg7008LExdrCXto6V/MsYZnteO6wKDEVg=
=nTrw
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.