-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 04 Jan 2026 17:27:30 +0100 Source: sogo Binary: sogo sogo-activesync sogo-activesync-dbgsym sogo-dbgsym Architecture: armhf Version: 5.8.0-2+deb12u1 Distribution: bookworm Urgency: high Maintainer: arm Build Daemon (arm-ubc-06) Changed-By: Tobias Frost Description: sogo - Scalable groupware server sogo-activesync - Scalable groupware server - ActiveSync module Closes: 1060925 1071163 1121952 Changes: sogo (5.8.0-2+deb12u1) bookworm; urgency=high . [ Tobias Frost ] * Non-maintainer upload. * Cherry-pick patch from salsa repo to fix below mentioned WSTG-INPV-02 issue. (The patch was present in the git repo, but the never released as part of a package) * CVE-2024-48104 - HTML Injection (Closes: #1060925) * CVE-2024-24510 - CSS Injection * CVE-2024-34462 - Cross Site Scripting (XSS) (Closes: #1071163) * CVE-2025-63498 - Cross Site Scripting (XSS) * CVE-2025-63499 - Cross Site Scripting (XSS) (Closes: #1121952) . [ Jordi Mallach ] * Add upstream fix for a WSTG-INPV-02 security issue, crash on invalid mailIdentities. Checksums-Sha1: a8e80b566cb0a581390e6871c4f0f181477814cd 98176 sogo-activesync-dbgsym_5.8.0-2+deb12u1_armhf.deb 5dd044d76ebe9e46069943eb86700095462841e8 222736 sogo-activesync_5.8.0-2+deb12u1_armhf.deb c464afe440bc2c7e3378876f03e0c13dbf52fda6 1174620 sogo-dbgsym_5.8.0-2+deb12u1_armhf.deb a373938a89c4969c006795d2cbcd56437b980e20 11010 sogo_5.8.0-2+deb12u1_armhf-buildd.buildinfo 6bf75389edbd5f4462facd1a9a1ba178c63e83f6 1205216 sogo_5.8.0-2+deb12u1_armhf.deb Checksums-Sha256: 4d868a926ed26f3f55d1807c4f8f706f1ed824d173b5d8e211755b4d50f1860d 98176 sogo-activesync-dbgsym_5.8.0-2+deb12u1_armhf.deb 912233e8eb0ff1b8c3a7c95824aa55ed472fa7bd9f2d209c6650c8ef9ba86e31 222736 sogo-activesync_5.8.0-2+deb12u1_armhf.deb ce3d8102c0896eb3b505f23564999a94cfb816385e88463e983d1ff742d1ac09 1174620 sogo-dbgsym_5.8.0-2+deb12u1_armhf.deb e7907d9ba676d63ff4ec69e07db4abe3b765ef925145d433dd543fed60c1d3b4 11010 sogo_5.8.0-2+deb12u1_armhf-buildd.buildinfo 2c769d7ffb2af0936d34d9bfa017f37c7a4f73905822b4bbddce8bfd59e4cbca 1205216 sogo_5.8.0-2+deb12u1_armhf.deb Files: 125efe5be3117db8cfe32cc673db8a47 98176 debug optional sogo-activesync-dbgsym_5.8.0-2+deb12u1_armhf.deb 5f3109b0ae015677663da3ecf43f291f 222736 mail optional sogo-activesync_5.8.0-2+deb12u1_armhf.deb 1c848239f6632ba348f85dbf9232f4c2 1174620 debug optional sogo-dbgsym_5.8.0-2+deb12u1_armhf.deb 2223f946e4a6bc84109e27a6e1362b20 11010 mail optional sogo_5.8.0-2+deb12u1_armhf-buildd.buildinfo 14585a77ee630b3979f70c551541850b 1205216 mail optional sogo_5.8.0-2+deb12u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEpxWVfktWxVoKRwGgJ7tNDw2WyRsFAmlav74ACgkQJ7tNDw2W yRvsrBAAtlQeefeToVi3NJEO8Y2/4zTPpwPfrjM7/9uSzMNHcmRnpnQQJ/bzka3Q toGOFu6xUaAKHrIJ+c9xuM+q9b7j7T+gje2O3XSzC9FJHjCN7TGzPvpvXBDuPHGR apweDqRcnl8WNfzuGIimiYNS3CMgIEFFv/oe5wDtmg6qBoAhrSbcHb5WHvH54286 y1yFuN5fs0fhQBpeZWvwf1MBvLKsUPKZeR4bqEVeTPHUQl/5AxMgb2sRJbaNv+g+ PkJiqAYErOQzSGAjxqoyOIJC95oX44fe8dWerMR4eql6PYKphRBbVmpo6rGNxv6l PTtrLfL7PEC9/jt9jWx0gnXCiSfQ0C7fwxHB6/CbiYX1/MBrYha7kqqj+lwXwKd/ 2R/6VVJ3fG75/hUCSgiVYuR/NQ75JBmVQoQYnU2K3pP4NwtQ4ExZWprlYnSVoo5W TzQKd4IJDC1x4YqVB7bO0Wsk4JOmDh7PBobNQdYEX3FXt2DLm0FTO3qLnUDxi5sW 9iHQBtqsjmDWFpaRDGEo1QNQMXpdpqxkfch247zNCUHO3evIJf0QnEDzevGDnXJo HNJe1L6SFNL9C8rXaFU6hJLReFv22QUcnW0qPQ+fBpywsM6gjfLQBRsON3+9H4A7 q0L7Fp3l+BzFr/PLG3xneToL0A7+k5Geesyezfmv6jkUVzLWEj8= =Y9lo -----END PGP SIGNATURE-----