https://seclists.org/oss-sec/2025/q3/4: DoS segfault (NULL pointer def) in SOPE / SOGo
Published Jul 2, 2025
·Updated
Affected Software
2 affected components
SOGo SOPE>=2.0.2
SOGo SOGo>=2.0.2
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
CVE-2025-XXXX is categorized as a denial-of-service vulnerability due to a segfault caused by a NULL pointer dereference.
2
How do I fix CVE-2025-XXXX?
To remedy CVE-2025-XXXX, upgrade to the latest version of SOGo that addresses this vulnerability.
3
What systems are affected by CVE-2025-XXXX?
All versions of SOGo since version 2.0.2 are impacted by CVE-2025-XXXX.
4
Can CVE-2025-XXXX be exploited remotely?
Yes, CVE-2025-XXXX can be triggered remotely using a crafted HTTP request.
5
What are the symptoms of CVE-2025-XXXX?
The primary symptom of CVE-2025-XXXX is a crash of the SOGo application, leading to service disruption.