* SECURITY UPDATE: lasso does not properly check the return value from the
OpenSSL DSA_verify function (LP: #317181).
- lasso/xml/tools.c: Correctly check for signature validity.
- CVE-2009-0050
-- Stefan Lesicnik <email address hidden> Wed, 14 Jan 2009 19:56:22 +0200
This bug was fixed in the package lasso - 2.2.0-1ubuntu0.1
---------------
lasso (2.2.0-1ubuntu0.1) intrepid-security; urgency=low
* SECURITY UPDATE: lasso does not properly check the return value from the
OpenSSL DSA_verify function (LP: #317181).
- lasso/xml/tools.c: Correctly check for signature validity.
- CVE-2009-0050
-- Stefan Lesicnik <email address hidden> Wed, 14 Jan 2009 19:56:22 +0200