VYPR

Lasso

by Entrouvert

CVEs (2)

  • CVE-2015-1783HigAug 11, 2017
    risk 0.49cvss 7.5epss 0.01

    The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.

  • CVE-2009-0050Jan 7, 2009
    risk 0.00cvss epss 0.00

    Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.