Debian Patches

Status for sogo/5.8.0-2+deb12u3

Patch Description Author Forwarded Bugs Origin Last update
disable_is_localhost_test.patch =================================================================== no
libxml2.patch =================================================================== no
0002-Change-sogo-backup-location-and-update-cronjob.patch Change sogo-backup location and update cronjob
Change sogo-backup location to /var/backups/sogo and update
sogo-backup.sh location in cronjob to /usr/sbin/sogo-backup.
Jeroen Dekkers <jeroen@dekkers.ch> no 2013-04-13
0003-Fix-may-be-used-uninitialized-in-this-function-warni.patch Fix "may be used uninitialized in this function" warnings.

===================================================================
Jeroen Dekkers <jeroen@dekkers.ch> yes 2014-04-09
0005-Remove-build-date.patch Remove build date Jeroen Dekkers <jeroen@dekkers.ch> no 2014-10-05
0006-Update-unit-test-expected-failures.patch Update unit test expected failures Jeroen Dekkers <jeroen@dekkers.ch> no 2016-04-09
disable_test_rendering.patch Disable test_rendering test unit This test is known to fail on several Debian architectures:
mips, s390x, hppa, powerpc, powerpcspe, ppc64: all of them being big endian.

===================================================================
Jordi Mallach <jordi@debian.org> no
0007-Do-not-use-OpenSSL-when-we-are-configured-to-use-Gnu.patch Do not use OpenSSL when we are configured to use GnuTLS Jeroen Dekkers <jeroen@dekkers.ch> no 2019-01-13
0008-Unset-MAKEFLAGS-and-MFLAGS-in-configure.patch Unset MAKEFLAGS and MFLAGS in configure
This fixes a build failure when building the package with parallel
make.
Jeroen Dekkers <jeroen@dekkers.ch> no 2019-01-13
0009-Omit-signedViewer-altogether-when-not-using-openssl.patch Omit signedViewer altogether when not using openssl Hanno Stock <hanno.stock@indurad.com> no 2019-07-30
python3.patch =================================================================== no
security_wstg-inpv-02_nsexception_fix.patch fix(security): Security fix for WSTG-INPV-02. Fix Crash / NSException where mailIdentities is invalid on init.

commit fe9ae12e46a151ee5989ed1f0009bb81611a46bd

fix(security): Security fix for WSTG-INPV-02. Fix NSException where tried to modify NSDictionary. Closes #5651.

diff --git a/SoObjects/SOGo/SOGoUserDefaults.m b/SoObjects/SOGo/SOGoUserDefaults.m
index 357f8ebe6..5073e29b2 100644
smizrahi <seb.mizrahi@gmail.com> yes upstream 2022-12-05
CVE-2025-63499.patch fix(vulnerability): prevent sogo to execute scripts pass in theme query Hivert Quentin <quentin.hivert.fr@gmail.com> yes debian upstream https://github.com/Alinto/sogo/commit/16ab99e7cf8db2c30b211f0d5e338d7f9e3a9efb 2025-11-26
CVE-2025-63498.patch fix(login): Only remember the login if the auth was successful Hivert Quentin <quentin.hivert.fr@gmail.com> yes upstream https://github.com/Alinto/sogo/commit/9e20190fad1a437f7e1307f0adcfe19a8d45184c 2025-10-02
CVE-2024-34462.patch fix(vulnerability): prevent cross-site scripting when previewing attachments Hivert Quentin <quentin.hivert.fr@gmail.com> no debian https://github.com/Alinto/sogo/commit/2e37e59ed140d4aee0ff2fba579ca5f83f2c5920 2024-04-03
CVE-2024-24510.patch fix(mail): Fix security @import css injection smizrahi <seb.mizrahi@gmail.com> no https://github.com/Alinto/sogo/commit/21468700718ed71774eaf2979ee59330fc569424 2024-01-23
CVE-2023-48104.patch fix(hmtl): prevent html injection of tag form Hivert Quentin <quentin.hivert.fr@gmail.com> no debian https://github.com/Alinto/sogo/commit/7481ccf37087c3f456d7e5a844da01d0f8883098 2023-11-06
CVE-2026-46445_CVE-2026-46446.patch fix(sql): use proper sql adaptor for usr source Hivert Quentin <quentin.hivert.fr@gmail.com> no backport, https://github.com/Alinto/sogo/commit/1f7e5d2b2c2047c44a6a9e05f73c36491cb96d21.diff 2026-03-24
CVE-2025-71276.patch fix(vulnerability): prevent xss with events, tasks and contacts categories Hivert Quentin <quentin.hivert.fr@gmail.com> no upstream, https://github.com/Alinto/sogo/commit/e9b3f2a43d7557e8416f6749df4ab4f9128af2d1.diff 2025-12-16
CVE-2026-33550.patch fix(vulnerability): properly change the totp code after disabling it Hivert Quentin <quentin.hivert.fr@gmail.com> no backport, https://github.com/Alinto/sogo/commit/83d4c522f87cfde0ba543837d9b24c3479083ec2.diff 2026-02-25
CVE-2026-8496.patch fix(mail): sanitise mail with ics (invitation to event) Hivert Quentin <quentin.hivert.fr@gmail.com> no upstream, https://github.com/Alinto/sogo/commit/67ce01ec2a1a7854d8e9f615dd65afb949043e8.diff 2026-05-03
CVE-2026-8496_regression_fix.patch fix(pref): prevent onevent cleaning to remove legitimate words Hivert Quentin <quentin.hivert.fr@gmail.com> no backport, https://github.com/Alinto/sogo/commit/c45233c11e250a22fa1e1f3e47fee2d6e232045b.diff 2026-05-19
CVE-2026-8851_1.patch fix(acl): only add existing uid Hivert Quentin <quentin.hivert.fr@gmail.com> no upstream, https://github.com/Alinto/sogo/commit/f9b71059f4f382d7b337d16ce1257443ade43d02.diff 2026-04-15
CVE-2026-8851_2.patch fix(acl): fix folder path Hivert Quentin <quentin.hivert.fr@gmail.com> no upstream, https://github.com/Alinto/sogo/commit/d902756aaf955a9ade6061806bb372e15b673197.diff 2026-04-21
fix_xss_message_subject_rendering_2.patch fix(mail): render properly the subject v2 Hivert Quentin <quentin.hivert.fr@gmail.com> no backport, https://github.com/Alinto/sogo/commit/29d0bbc9eb96c2b4a0ada4d93eac79a66c789b22.diff 2026-05-03
git_clean_import_event.patch commit b18f1a09f59424a36f6de5aa7c30e6f27405c15d

fix(event): clean import of event

diff --git a/SoObjects/Appointments/SOGoAppointmentFolder.m b/SoObjects/Appointments/SOGoAppointmentFolder.m
index f18c7ad77..f958eab51 100644
Hivert Quentin <quentin.hivert.fr@gmail.com> no 2026-05-26

All known versions for source package 'sogo'

Links