-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 04 Jan 2026 17:27:30 +0100 Source: sogo Binary: sogo sogo-activesync sogo-activesync-dbgsym sogo-dbgsym Architecture: s390x Version: 5.8.0-2+deb12u1 Distribution: bookworm Urgency: high Maintainer: s390x Build Daemon (zani) Changed-By: Tobias Frost Description: sogo - Scalable groupware server sogo-activesync - Scalable groupware server - ActiveSync module Closes: 1060925 1071163 1121952 Changes: sogo (5.8.0-2+deb12u1) bookworm; urgency=high . [ Tobias Frost ] * Non-maintainer upload. * Cherry-pick patch from salsa repo to fix below mentioned WSTG-INPV-02 issue. (The patch was present in the git repo, but the never released as part of a package) * CVE-2024-48104 - HTML Injection (Closes: #1060925) * CVE-2024-24510 - CSS Injection * CVE-2024-34462 - Cross Site Scripting (XSS) (Closes: #1071163) * CVE-2025-63498 - Cross Site Scripting (XSS) * CVE-2025-63499 - Cross Site Scripting (XSS) (Closes: #1121952) . [ Jordi Mallach ] * Add upstream fix for a WSTG-INPV-02 security issue, crash on invalid mailIdentities. Checksums-Sha1: 9364bfee515d8c8857b2b2a39df783b71cca55f8 95216 sogo-activesync-dbgsym_5.8.0-2+deb12u1_s390x.deb 15f7a0b99f9b7c271346c3278113b8c6ceac5743 203720 sogo-activesync_5.8.0-2+deb12u1_s390x.deb 508d0c5196e110bbd52612d4eef4a74ed842839e 1100776 sogo-dbgsym_5.8.0-2+deb12u1_s390x.deb 958418005fd144a2b1a828ae12cf601a04a2bd04 11054 sogo_5.8.0-2+deb12u1_s390x-buildd.buildinfo d1ed6eb117c650c8348df045ddfb30eea127665f 1241128 sogo_5.8.0-2+deb12u1_s390x.deb Checksums-Sha256: dd08cc7c4cca482eda2cd3d2e41a1deb8f90f9b89f0640509851226a9ab3c873 95216 sogo-activesync-dbgsym_5.8.0-2+deb12u1_s390x.deb 782704aa4e7a919820337041baac0bdffa2ff342b067f484a9badcede778810c 203720 sogo-activesync_5.8.0-2+deb12u1_s390x.deb e3592fd2c06c7866cbf71fc8abe5e26b59fbcd9e625877ddeeda2c44ee1a2315 1100776 sogo-dbgsym_5.8.0-2+deb12u1_s390x.deb e1910e4fd9e6a9efd6debb8fa7f0787e7bddff7359dfa8d3e0ceed2ca005da1b 11054 sogo_5.8.0-2+deb12u1_s390x-buildd.buildinfo 3a5794738c6f5869c3042a7c6ca62043e278e8bfeb1feb6616cd5c0cdbdf630f 1241128 sogo_5.8.0-2+deb12u1_s390x.deb Files: 9179daee11f077d9cc2be0fb0e89d0ed 95216 debug optional sogo-activesync-dbgsym_5.8.0-2+deb12u1_s390x.deb 460e71c9e6e427bc176c843fb4cec4d9 203720 mail optional sogo-activesync_5.8.0-2+deb12u1_s390x.deb c9096039ab487d57ba2a876259c4e127 1100776 debug optional sogo-dbgsym_5.8.0-2+deb12u1_s390x.deb 3cb57f09f290c71d44ae12ba429464b6 11054 mail optional sogo_5.8.0-2+deb12u1_s390x-buildd.buildinfo 84a88d0f8b61c4be95f2d5da03794f98 1241128 mail optional sogo_5.8.0-2+deb12u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEgh4msZ+e2PZfd5KckaCrxAR3BY0FAmlav70ACgkQkaCrxAR3 BY0pwhAAhIJJv3p7QhvlGSz49Y//gvjftbJa+jf1osQXZ2FYR0ohs5oXgIKH9IsG ELS9Rk4UZCTejhuhWot/rxCkOQpnHT/V1xSuZ7+Lyft9ldx2sGCDlHT5D84Nc0r4 LVhLZausVSTt/4XkMfWUI54wZ+t2oFeMEYjB+14l1KicR6sqM4oANIQmtfca3cdp fzdPuXabBmr50qGsRP31bri73UiWKm2sfpwrT0nufJe46Tes0k+xUjC49gxz2S8J ieOEcNcekTEKd+pYdymBsvTH03lteNsLy4Kf9OfxRCibT0qF3D3ehtoVQRtuePnj 0ES/NGI4sPaUy/0DOmjhX2mBa9n2GWUJbus1rZE1nCKoNOW7lk8mFPP0PyqSkQ1E AItYHc/WysPwGG3rhpNuuPYivaNspEkN8fcc6VhVnwmcQQN0fbtJoz4pR+XwZkWu or62m3HGHo1oO9DlVfyXtwm1gRs5GR3htSsm/EmdcRFyeuC3cqjr4lfsbRyshqnV n5j7kzPjraTxsEKslUKOmd+UHWJ2umxNi7wRPQNT1SaU47bCAc7vYEzKruVGQj/h 3labMfPOnZnNGm/fBKntcHBqpIFYHmN3DkjJtf28XffH44u8uHNxqHiljtfQRklK AQPOHLKrFORDS0Zl9gOk0FQnTqDhsL9aiO7fRn3cdK0pf9epI94= =1kic -----END PGP SIGNATURE-----