PT-2025-28029 · Alinto+1 · Sogo+1
Stefan Bühler
·
Published
2025-07-05
·
Updated
2025-10-31
·
CVE-2025-53603
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Alinto SOPE SOGo versions 2.0.2 through 5.12.2
Description
This issue involves a NULL pointer dereference in
sope-core/NGExtensions/NGHashMap.m that can lead to a crash of the SOGo application. The vulnerability occurs when a request contains a parameter in the query string that duplicates a parameter in the POST body. Approximately 30,000 installations of SOGo are tracked in the Russian internet space, with an estimated 98% being vulnerable. While mass exploitation has not been observed, the vulnerability allows for remote, unauthenticated denial-of-service attacks.Recommendations
Update SOGo to version 5.12.3 or later to resolve this issue.
Restart the service to reset active sessions.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Sogo