CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. | 7.5 |
High |
||
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors. | 7.5 |
High |
||
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. | 4.3 |