CVE-2017-11342: Input Validation
Published Jul 16, 2017
·Updated
There is an illegal address access in ast.cpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
Affected Software
1 affected component
LibSass LibSass=3.4.5
Event History
Jul 16, 2017
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11342?
CVE-2017-11342 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-11342?
To fix CVE-2017-11342, update to a patched version of LibSass that addresses this vulnerability.
3
What causes the vulnerability in CVE-2017-11342?
CVE-2017-11342 is caused by illegal address access in the ast.cpp file of LibSass 3.4.5.
4
Can CVE-2017-11342 be exploited remotely?
Yes, CVE-2017-11342 can lead to a remote denial of service attack if exploited.
5
Which version of LibSass is affected by CVE-2017-11342?
LibSass version 3.4.5 is affected by CVE-2017-11342.