Debian alert DLA-4260-1 (sope)
From: | Chris Lamb <lamby@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 4260-1] sope security update | |
Date: | Sat, 02 Aug 2025 16:43:02 -0400 | |
Message-ID: | <175416735288.10527.16336337058047990006@copycat> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4260-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb August 02, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : sope Version : 5.0.1-2+deb11u1 CVE ID : CVE-2025-53603 Debian Bug : 1108798 Stefan Buehler discovered a flaw in sope, the set of Objective-C frameworks powering SOGo, which may result in denial of service via a specially crafted POST request. For Debian 11 bullseye, this problem has been fixed in version 5.0.1-2+deb11u1. We recommend that you upgrade your sope packages. For the detailed security status of sope please refer to its security tracker page at: https://security-tracker.debian.org/tracker/sope Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmiOcuUACgkQHpU+J9Qx Hlh9RxAAp5m8Wu2FFAXmHfLEqWgWIt1cuY5klw0VmiRy7MD43H4F5JaS7S/vu4Lo BGORovVCum29J9CwpTR23HaOWlzUF/r5jQXU487ySrV6p8ywsODNkL5HZT3piuI8 onHEr6ssKoaxKkkxWG4fQuagOw3ScYr2ftEWm0ZXIGXhPt3C1k2JDDdvrC5apWls g9/ae0DWg9YURcfmE0HSALf7GmshN2DrfbszqTOd8qGTlyBrDEW/pZhBnUGB3tJc 9YHh8Et/bJYevwq1n4iS7wRbwzqVAMFXTi4dABjh7nPyYZNsGZMJ4fu6uV2l7SGX y1Q/cZ64N8jaDxWAthjAmm1KJV+hkTl3lONqI9jxWGiAJGUGHMcipFvU7gZl7ZFX AKXte6FzMBY/taHz9HnsxZ+CpCt7IE4oorz7aRuLvi0nfQ72aUXQ11oqL0mDuGgX xvEfQY+kjoXhoto9sAXIQb04CtkfJecuoUNqXbit6tOPelHVoZ0y6y8LPWR2TB7I 5m1ttSPDZ4T9bAbvz6/MDzNlZ72DnR97/Hsg9XG/sqcHG99g2zPlHetugg/ISOpI mnx4Pe29S+TVLfjqOuFuKin/iz/esvIFoH3oHSHp2Q/K7gcd63nl1u/05TBfGW1A taU79gSBgzwZUIZTVT5L9/qCraFoRQaZV2QL7liqx0n08gk+6S0= =CdAz -----END PGP SIGNATURE-----