MidnightBSD

Advisories for entrouvert

CVE-2009-0050 MEDIUM

Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
entrouvert lasso 2.0.0-1
entrouvert lasso 1.9.9.0
entrouvert lasso *
CVE-2015-1783 MEDIUM

The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
fedoraproject fedora 20
fedoraproject fedora 21
entrouvert lasso *
fedoraproject fedora 22