PT-2009-6711 · Lasso+1 · Lasso+4

Published

1970-01-01

·

Updated

2018-10-11

·

CVE-2009-0050

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Lasso versions prior to 2.2.1 liblasso3-dev (affected versions not specified) liblasso3 (affected versions not specified) liblasso-java (affected versions not specified)
Description The issue is related to multiple vulnerabilities in the Lasso and liblasso packages, which can lead to a breach of protected information integrity. These vulnerabilities can be exploited remotely. The problem with Lasso 2.2.1 and earlier is that it does not properly check the return value from the OpenSSL DSA verify function, allowing remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature.
Recommendations For Lasso versions prior to 2.2.1, update to a version that properly checks the return value from the OpenSSL DSA verify function. For liblasso3-dev, liblasso3, and liblasso-java, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03331
BDU:2015-03332
BDU:2015-03333
CVE-2009-0050
DSA-1700-1

Affected Products

Lasso
Openssl
Liblasso-Java
Liblasso3
Liblasso3-Dev