Packages
- lasso - Liberty Alliance and SAML protocol Library
Details
It was discovered that Lasso incorrectly handled certain malformed SAML
responses. A remote attacker could possibly use this issue to cause Lasso
to crash, resulting in a denial of service. (CVE-2025-46404)
It was discovered that Lasso incorrectly handled certain malformed SAML
assertion responses. A remote attacker could possibly use this issue to
cause Lasso to crash, resulting in a denial of service. (CVE-2025-46705)
It was discovered that Lasso incorrectly handled certain malformed SAML
responses. A remote attacker could possibly use this issue to cause Lasso
to consume memory, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS. (CVE-2025-46784)
It was discovered that Lasso incorrectly handled certain malformed SAML
responses. A remote attacker could use this issue to cause Lasso to...
It was discovered that Lasso incorrectly handled certain malformed SAML
responses. A remote attacker could possibly use this issue to cause Lasso
to crash, resulting in a denial of service. (CVE-2025-46404)
It was discovered that Lasso incorrectly handled certain malformed SAML
assertion responses. A remote attacker could possibly use this issue to
cause Lasso to crash, resulting in a denial of service. (CVE-2025-46705)
It was discovered that Lasso incorrectly handled certain malformed SAML
responses. A remote attacker could possibly use this issue to cause Lasso
to consume memory, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS. (CVE-2025-46784)
It was discovered that Lasso incorrectly handled certain malformed SAML
responses. A remote attacker could use this issue to cause Lasso to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2025-47151)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 25.04 plucky | liblasso-perl – 2.8.2-8ubuntu0.1 | ||
| liblasso3t64 – 2.8.2-8ubuntu0.1 | |||
| python3-lasso – 2.8.2-8ubuntu0.1 | |||
| 24.04 LTS noble | liblasso-perl – 2.8.2-2ubuntu0.1 | ||
| liblasso3t64 – 2.8.2-2ubuntu0.1 | |||
| python3-lasso – 2.8.2-2ubuntu0.1 | |||
| 22.04 LTS jammy | liblasso-perl – 2.7.0-2ubuntu0.1 | ||
| liblasso3 – 2.7.0-2ubuntu0.1 | |||
| python3-lasso – 2.7.0-2ubuntu0.1 | |||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.