Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
| Software | From | Fixed in |
|---|---|---|
| entrouvert / lasso | 1.9.9.0 | 1.9.9.0.x |
| entrouvert / lasso | 2.0.0-1 | 2.0.0-1.x |
| entrouvert / lasso | - | 2.2.1-0.x |