-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 04 Jan 2026 17:27:30 +0100 Source: sogo Binary: sogo sogo-activesync sogo-activesync-dbgsym sogo-dbgsym Architecture: armel Version: 5.8.0-2+deb12u1 Distribution: bookworm Urgency: high Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Tobias Frost Description: sogo - Scalable groupware server sogo-activesync - Scalable groupware server - ActiveSync module Closes: 1060925 1071163 1121952 Changes: sogo (5.8.0-2+deb12u1) bookworm; urgency=high . [ Tobias Frost ] * Non-maintainer upload. * Cherry-pick patch from salsa repo to fix below mentioned WSTG-INPV-02 issue. (The patch was present in the git repo, but the never released as part of a package) * CVE-2024-48104 - HTML Injection (Closes: #1060925) * CVE-2024-24510 - CSS Injection * CVE-2024-34462 - Cross Site Scripting (XSS) (Closes: #1071163) * CVE-2025-63498 - Cross Site Scripting (XSS) * CVE-2025-63499 - Cross Site Scripting (XSS) (Closes: #1121952) . [ Jordi Mallach ] * Add upstream fix for a WSTG-INPV-02 security issue, crash on invalid mailIdentities. Checksums-Sha1: 428af4ff7144756ae24dcc13f78916b7f3a7296e 97912 sogo-activesync-dbgsym_5.8.0-2+deb12u1_armel.deb d6abe15bdfb8360ccee62f20a61aeb76f7a02d0c 223992 sogo-activesync_5.8.0-2+deb12u1_armel.deb 268824f1bffbf099106d401d277923e83de14dae 1171716 sogo-dbgsym_5.8.0-2+deb12u1_armel.deb 69c63d56f435dacc0ec26ab19355288c7719cf8d 11008 sogo_5.8.0-2+deb12u1_armel-buildd.buildinfo 406d3d0f01ee29be2ef56c50d03c1866ef0c7609 1204908 sogo_5.8.0-2+deb12u1_armel.deb Checksums-Sha256: a7a475c7a0ec24b4e352fb7329f0f1dc68e66e77d54d2c5b55b00c47293bb387 97912 sogo-activesync-dbgsym_5.8.0-2+deb12u1_armel.deb 8421dc05630527544a93fbeb7b44902b21c27cdaa1242bb75fe08f2034258c7a 223992 sogo-activesync_5.8.0-2+deb12u1_armel.deb ac3c2f42e5d9a02257c63ac0465c74171eddaff782b16ab6cae5f0ea9a40927f 1171716 sogo-dbgsym_5.8.0-2+deb12u1_armel.deb 63e08b838708ca1b26294731c7f9b008dc5008d3d8794d70d70cc16451effb1e 11008 sogo_5.8.0-2+deb12u1_armel-buildd.buildinfo 7175cc380a93e4076cf5b60d104d0172525a543d864dcfd1f405f45b4a7372c3 1204908 sogo_5.8.0-2+deb12u1_armel.deb Files: 39a71b0deec1742812e38858cd9c27e4 97912 debug optional sogo-activesync-dbgsym_5.8.0-2+deb12u1_armel.deb 39b0b586c369233db5f1dab17cf7fa9b 223992 mail optional sogo-activesync_5.8.0-2+deb12u1_armel.deb 472c4caa28f88ff39a5beeda1c302d23 1171716 debug optional sogo-dbgsym_5.8.0-2+deb12u1_armel.deb 26423d4aef35bacb2b5235f58d1bbef0 11008 mail optional sogo_5.8.0-2+deb12u1_armel-buildd.buildinfo 998123685a4379be7c1865c3cd4a2d3e 1204908 mail optional sogo_5.8.0-2+deb12u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmlav9QACgkQOQKMdMnE H5PTJQ/+JXLMjBu/Gh950W8HVDRifrxBgFxIvvg5ej+M5A/HIV3BPzR0+zHgLDfV r5iC/0h1Zt5AWEc+KfTPV2tMGMdpxXPMyuLXgc1e3gkJFhH851A0QSwhG3tFNiHp TN2YwwU00rtfIE1zQUt96D6WpqNzVojmYj4qwJ2hmlkrLD7WEIp5QrCfATHbcAFx l/Zp6ikKnbCNOHDCjQvsemMMZqPfJnbp/zHuYYDxmGzUBcD1hPNy6l5diUM//N3o ciUSYRe2og3zLe9zPZ3g6L8dHC/rHUuTnI0167ptgBE9jrH2Y7c1jT9bVtr/WP3b k1EB6OqOlcXHLYMKSy3Nzn64THylC6ij/yZDx8JlsP2EACoD0znishd557iWjFM/ /HTbHkNa9oQoqiI01DlFSJXl/M0QaC2+T0ciwcHcCu7Q/UOdSPvW+El20tAJFJBy vyD80sf061rcHAEy+7XymaaYxa9x2StWYCoA8RONIWxQyGsZ+GA9fohVFMVMLFCR Yu/LCn1mipXp9X0ipdEyJ1GPCTaRi2HSz+QroDeWDDgIdr6sI8yUV+ET1ZQY/vcX kBXlblPGr3/qLQbaKceNT9btWfMWGMACFmpeFNr+2GVQSTtrRlbIkQ9B8F+UWUvZ TxeCXjOj70DW7V/Ube+C9JPhM49uDuogD9MhOxtYB3FZckomVPA= =onHY -----END PGP SIGNATURE-----