CVE-2025-53603: Null Pointer Dereference
In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53603?
CVE-2025-53603 has a medium severity level due to the potential for a NULL pointer dereference leading to application crashes.
How do I fix CVE-2025-53603?
To fix CVE-2025-53603, it is recommended to update Alinto SOGo to version 5.12.3 or higher.
What versions of Alinto SOGo are affected by CVE-2025-53603?
CVE-2025-53603 affects versions of Alinto SOGo from 2.0.2 to 5.12.2.
What is the impact of CVE-2025-53603 on SOGo users?
The impact of CVE-2025-53603 on SOGo users includes potential application crashes when specific query parameters are duplicated.
Is there a workaround for CVE-2025-53603 if I cannot update?
A temporary workaround for CVE-2025-53603 involves avoiding requests that contain duplicate parameters in the query string and POST body.