PT-2009-6711 · Lasso+1 · Lasso+4

Publicado

1970-01-01

·

Atualizado

2018-10-11

·

CVE-2009-0050

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Lasso versions prior to 2.2.1 liblasso3-dev (affected versions not specified) liblasso3 (affected versions not specified) liblasso-java (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the Lasso and liblasso packages, which can lead to a breach of protected information integrity. These vulnerabilities can be exploited remotely. The problem with Lasso 2.2.1 and earlier is that it does not properly check the return value from the OpenSSL DSA verify function, allowing remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature.
Recommendations For Lasso versions prior to 2.2.1, update to a version that properly checks the return value from the OpenSSL DSA verify function. For liblasso3-dev, liblasso3, and liblasso-java, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03331
BDU:2015-03332
BDU:2015-03333
CVE-2009-0050
DSA-1700-1

Produtos afetados

Lasso
Openssl
Liblasso-Java
Liblasso3
Liblasso3-Dev