LWN.net Logo

lasso: certificate verification bypass

Package(s):lasso CVE #(s):CVE-2009-0050
Created:January 12, 2009 Updated:January 14, 2009
Description:

From the CVE entry:

Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

Alerts:
Debian DSA-1700-1 2009-01-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds