CVE-2025-46404: Null Pointer Dereference
A denial of service vulnerability exists in the lassoproviderverifysamlsignature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46404?
CVE-2025-46404 is categorized as a denial of service vulnerability.
How does CVE-2025-46404 affect Entr'ouvert Lasso?
CVE-2025-46404 affects Entr'ouvert Lasso 2.5.1 by allowing attackers to send malformed SAML responses.
What impact does a successful exploit of CVE-2025-46404 have?
A successful exploit of CVE-2025-46404 can lead to a denial of service, causing the application to become unresponsive.
How can I mitigate CVE-2025-46404?
Mitigating CVE-2025-46404 involves updating Entr'ouvert Lasso to a patched version that addresses this vulnerability.
Who is affected by CVE-2025-46404?
Users and organizations using Entr'ouvert Lasso 2.5.1 are affected by CVE-2025-46404.