First published: Mon Jun 04 2018(Updated: )
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::skip_over_scopes which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libsass | <=3.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11693 is a vulnerability in LibSass version 3.5.4 that allows an out-of-bounds read of a memory region, leading to potential information disclosure or denial of service.
CVE-2018-11693 has a severity rating of 8.1 (high).
CVE-2018-11693 can be exploited by leveraging an out-of-bounds read in the function Sass::Prelexer::skip_over_scopes, allowing an attacker to disclose information or cause a denial of service.
LibSass versions up to and including 3.5.4 are affected by CVE-2018-11693.
LibSass versions after 3.5.4 have addressed the vulnerability and should be updated to mitigate the issue.