{"id":"CVE-2016-6189","details":"Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.","modified":"2026-08-07T14:31:45.226351Z","published":"2017-02-17T17:59:00.797Z","references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/07/09/3"},{"type":"FIX","url":"https://github.com/inverse-inc/sogo/commit/717f45f640a2866b76a8984139391fae64339225"},{"type":"FIX","url":"https://github.com/inverse-inc/sogo/commit/875a4aca3218340fd4d3141950c82c2ff45b343d"},{"type":"EVIDENCE","url":"https://sogo.nu/bugs/view.php?id=3695"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alinto/sogo","events":[{"introduced":"0"},{"fixed":"7434cc4cf5b7b968c3ff8cacd5add69b4807e478"},{"introduced":"fe0221f6300bc92f0156f9dde4e58c1c8d3610e7"},{"fixed":"9a2ce5532a4906ee79b4fe6d70a9dbcab1d52019"},{"fixed":"717f45f640a2866b76a8984139391fae64339225"},{"fixed":"875a4aca3218340fd4d3141950c82c2ff45b343d"}],"database_specific":{"cpe":"cpe:2.3:a:alinto:sogo:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.3.12"},{"introduced":"3.0.0"},{"fixed":"3.1.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["SOGo-3.1.0","SOGo-2.3.11","SOGo-2.3.10","SOGo-2.3.9","SOGo-3.0.2","SOGo-2.3.8","SOGo-3.0.1","SOGo-3.0.0","SOGo-2.3.7a","SOGo-2.3.7","SOGo-2.3.6","SOGo-2.3.5","SOGo-2.3.4","SOGo-2.3.3a","SOGo-2.3.3","SOGo-2.3.2","SOGo-2.3.1","SOGo-2.3.0","SOGo-2.2.17a","SOGo-2.2.20","SOGo-2.0.2","SOGo-2.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6189.json","vanir_signatures_modified":"2026-08-07T14:31:45Z","vanir_signatures":[{"digest":{"line_hashes":["272275947418062989887012245545970907197","237761867161411648712498103835426187177","231454080872523687104751719403681284838","193563563261601370690713969555675233477"],"threshold":0.9},"id":"CVE-2016-6189-06b8778f","signature_type":"Line","signature_version":"v1","source":"https://github.com/alinto/sogo/commit/717f45f640a2866b76a8984139391fae64339225","target":{"file":"SoObjects/SOGo/SOGoUserSettings.h"},"deprecated":false},{"digest":{"line_hashes":["272275947418062989887012245545970907197","237761867161411648712498103835426187177","231454080872523687104751719403681284838","193563563261601370690713969555675233477"],"threshold":0.9},"id":"CVE-2016-6189-26f1ac38","signature_type":"Line","signature_version":"v1","source":"https://github.com/alinto/sogo/commit/875a4aca3218340fd4d3141950c82c2ff45b343d","target":{"file":"SoObjects/SOGo/SOGoUserSettings.h"},"deprecated":false}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}