Description
In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo crash via a request in which a parameter in the query string is a duplicate of a parameter in the POST body.
Problem types
CWE-476 NULL Pointer Dereference
Product status
SOGo 2.0.2 (custom)
References
www.openwall.com/lists/oss-security/2025/07/02/3
lists.debian.org/debian-lts-announce/2025/08/msg00001.html
www.openwall.com/lists/oss-security/2025/07/05/1
github.com/Alinto/sope/compare/SOGo-2.0.1...SOGo-2.0.2
www.openwall.com/lists/oss-security/2025/07/02/3
github.com/...ef7d0f32064/sope-core/NGExtensions/NGHashMap.m
github.com/Alinto/sope/pull/69
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.