A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Lasso | Entrouvert | 2.5.1 (including) | 2.5.1 (including) |
| Lasso | Ubuntu | jammy | * |
| Lasso | Ubuntu | noble | * |
| Lasso | Ubuntu | plucky | * |
| Lasso | Ubuntu | upstream | * |