CVE-2009-0050 Information

Description

Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature a similar vulnerability to CVE-2008-5077.

Reference

http://www.ocert.org/advisories/ocert-2008-016.html http://www.securityfocus.com/archive/1/499827/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/47837

Share on: