CVE-2009-0050Improper Input Validation in Lasso

Severity
4.3MEDIUMNVD
OSV5.8
EPSS
0.1%
top 64.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 7
Latest updateMay 2

Description

Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/lasso< lasso 2.2.1-2 (bookworm)
Debianentrouvert/lasso< 2.2.1-2+3
NVDentrouvert/lasso2.2.1-0+2

🔴Vulnerability Details

2
GHSA
GHSA-7ccf-7vx8-76vm: Lasso 22022-05-02
OSV
CVE-2009-0050: Lasso 22009-01-07

📋Vendor Advisories

1
Debian
CVE-2009-0050: lasso - Lasso 2.2.1 and earlier does not properly check the return value from the OpenSS...2009