Search CVE reports


Toggle filters

1 – 7 of 7 results


CVE-2025-47151

Medium priority

Some fixes available 3 of 6

A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to an arbitrary code execution. An attacker can send a...

1 affected package

lasso

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lasso Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-46784

Medium priority

Some fixes available 1 of 4

A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of...

1 affected package

lasso

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lasso Not affected Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-46705

Medium priority

Some fixes available 3 of 6

A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lead to a denial of service. An attacker can send a...

1 affected package

lasso

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lasso Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-46404

Medium priority

Some fixes available 3 of 6

A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed...

1 affected package

lasso

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lasso Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2021-28091

Medium priority

Some fixes available 4 of 5

Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.

1 affected package

lasso

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lasso Not affected Not affected Fixed Fixed
Show less packages

CVE-2015-1783

Medium priority
Ignored

The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash)...

1 affected package

lasso

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lasso Not affected
Show less packages

CVE-2009-0050

Medium priority
Fixed

Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar...

1 affected package

lasso

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lasso
Show less packages