CVE-2017-11556: High severity centos libssh2 vulnerability
Published Jul 23, 2017
·Updated
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
Affected Software
1 affected component
LibSass LibSass=3.4.5
Event History
Jul 23, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11556?
CVE-2017-11556 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-11556?
To mitigate CVE-2017-11556, upgrade to a newer version of LibSass that addresses this vulnerability.
3
What software is affected by CVE-2017-11556?
CVE-2017-11556 specifically affects LibSass version 3.4.5.
4
What is the impact of exploiting CVE-2017-11556?
Exploiting CVE-2017-11556 can lead to remote denial of service due to stack consumption.
5
Is CVE-2017-11556 present in earlier versions of LibSass?
CVE-2017-11556 affects only LibSass 3.4.5, so earlier versions may not be impacted.