PT-2009-6711 · Lasso+1 · Lasso+4
Published
1970-01-01
·
Updated
2018-10-11
·
CVE-2009-0050
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Lasso versions prior to 2.2.1
liblasso3-dev (affected versions not specified)
liblasso3 (affected versions not specified)
liblasso-java (affected versions not specified)
Description
The issue is related to multiple vulnerabilities in the Lasso and liblasso packages, which can lead to a breach of protected information integrity. These vulnerabilities can be exploited remotely. The problem with Lasso 2.2.1 and earlier is that it does not properly check the return value from the OpenSSL DSA verify function, allowing remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature.
Recommendations
For Lasso versions prior to 2.2.1, update to a version that properly checks the return value from the OpenSSL DSA verify function.
For liblasso3-dev, liblasso3, and liblasso-java, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lasso
Openssl
Liblasso-Java
Liblasso3
Liblasso3-Dev