https://seclists.org/oss-sec/2025/q3/6: DoS segfault (NULL pointer def) in SOPE / SOGo
Published Jul 5, 2025
·Updated
Affected Software
1 affected component
SOGo SOPE>=2.0.2
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
CVE-2025-XXXX is classified as a critical denial-of-service vulnerability.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, update SOGo to the latest patched version that addresses this vulnerability.
3
Which versions are affected by CVE-2025-XXXX?
CVE-2025-XXXX affects all versions of SOGo since 2.0.2 released in 2012.
4
What is the nature of the vulnerability in CVE-2025-XXXX?
CVE-2025-XXXX involves a denial-of-service condition resulting from a NULL pointer dereference.
5
Can CVE-2025-XXXX be exploited remotely?
Yes, CVE-2025-XXXX can be exploited remotely using simple HTTP requests.