CVE-2009-0050

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
07/01/2009
Last modified:
09/04/2025

Description

Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:entrouvert:lasso:*:*:*:*:*:*:*:* 2.2.1-0 (including)
cpe:2.3:a:entrouvert:lasso:1.9.9.0:*:*:*:*:*:*:*
cpe:2.3:a:entrouvert:lasso:2.0.0-1:*:*:*:*:*:*:*