sogo (5.12.10-1)
[PTS] [DDPO]
OK: VCS matches the version in the archive
- Git: https://salsa.debian.org/debian/sogo.git
-
- Branch: debian
- Path: debian/changelog
- Repo size: 13205504
- Browser: https://salsa.debian.org/debian/sogo
- Last scan: 2026-08-18 12:23:03+00
- Error: https://salsa.debian.org/api/v4/projects/debian%2Fsogo API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
- Next scan: 2026-08-26 05:15:00+00
- Debian changelog in Git:
sogo (5.12.10-1) unstable; urgency=medium
* New upstream release with several security bugfixes:
- possible SQL injection with specific request
- several possible XSS injections with malicious mail
- possible SSRF with specific request
- possible shell injection when using sendmail
* Drop cherry-picked event import patch from 5.12.9-1.
* Drop source package Priority field, no longer needed.
* Drop Rules-Requires-Root field, now an implicit default.
* Add patch to use the correct regex template in html injection fix.
* Make test_rendering's named-value ordering check order-independent.
-- Jordi Mallach <jordi@debian.org> Tue, 18 Aug 2026 00:36:57 +0200
- This branch is even with tag debian/5.12.10-1