CVE-2017-11608: Medium severity centos libssh2 vulnerability
Published Jul 24, 2017
·Updated
There is a heap-based buffer over-read in the Sass::Prelexer::relinebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
Affected Software
1 affected component
LibSass LibSass=3.4.5
Event History
Jul 24, 2017
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11608?
CVE-2017-11608 has a severity rating that indicates it can lead to a remote denial of service attack.
2
How do I fix CVE-2017-11608?
To fix CVE-2017-11608, upgrade LibSass to a version higher than 3.4.5.
3
What software is affected by CVE-2017-11608?
CVE-2017-11608 specifically affects LibSass version 3.4.5.
4
What type of vulnerability is CVE-2017-11608?
CVE-2017-11608 is a heap-based buffer over-read vulnerability.
5
What is the impact of exploiting CVE-2017-11608?
Exploiting CVE-2017-11608 can result in a remote denial of service situation.