The prefix variable in the getordefine_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.
{ "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.4.1-1build1", "binary_name": "liblasso-perl" }, { "binary_version": "2.4.1-1build1", "binary_name": "liblasso-perl-dbgsym" }, { "binary_version": "2.4.1-1build1", "binary_name": "liblasso3" }, { "binary_version": "2.4.1-1build1", "binary_name": "liblasso3-dev" }, { "binary_version": "2.4.1-1build1", "binary_name": "php5-lasso" }, { "binary_version": "2.4.1-1build1", "binary_name": "python-lasso" } ], "availability": "No subscription required" }