CVE-2018-11499: Use After Free
Published May 26, 2018
·Updated
A use-after-free vulnerability exists in handleerror() in sasscontext.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 that could be leveraged to cause a denial of service (application crash) or possibly unspecified other impact.
Affected Software
1 affected component
Sass-lang Libsass>=3.4.0<=3.5.4
Event History
May 26, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11499?
CVE-2018-11499 is a use-after-free vulnerability in handle_error() in sass_context.cpp in LibSass which could cause a denial of service or other impact.
2
How severe is CVE-2018-11499?
CVE-2018-11499 has a severity rating of critical with a CVSS score of 9.8.
3
Which software versions are affected by CVE-2018-11499?
Versions 3.4.x and 3.5.x through 3.5.4 of LibSass are affected by CVE-2018-11499.
4
How can CVE-2018-11499 be exploited?
CVE-2018-11499 can be exploited by leveraging the use-after-free vulnerability in handle_error() in sass_context.cpp in LibSass.
5
Is there a fix for CVE-2018-11499?
Yes, updating LibSass to version 3.5.5 or later resolves CVE-2018-11499.