Title : Lasso OpenSSL "DSA_verify()" Signature Spoofing Vulnerability VUPEN ID : VUPEN/ADV-2009-0041 CVE ID : CVE-2009-0050 CWE ID : CWE-347
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2009-01-08
Technical Description
A vulnerability has been identified in Lasso, which could be exploited by attackers to bypass security restrictions. This issue is caused due to various functions not properly checking the result of the OpenSSL "DSA_verify()" function when validating signatures, which could cause a malformed signature to be treated as valid, leading to spoofing and phishing attacks.