Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lasso | Entrouvert | * | 2.7.0 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | lasso-0:2.5.1-8.el7_9 | * |
Red Hat Enterprise Linux 8 | RedHat | lasso-0:2.6.0-12.el8 | * |
Lasso | Ubuntu | bionic | * |
Lasso | Ubuntu | esm-apps/xenial | * |
Lasso | Ubuntu | focal | * |
Lasso | Ubuntu | groovy | * |
Lasso | Ubuntu | hirsute | * |
Lasso | Ubuntu | trusty | * |
Lasso | Ubuntu | xenial | * |