CVE-2018-11693: High severity libsass vulnerability
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::skipoverscopes which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-11693?
CVE-2018-11693 is a vulnerability in LibSass version 3.5.4 that allows an out-of-bounds read of a memory region, leading to potential information disclosure or denial of service.
How severe is CVE-2018-11693?
CVE-2018-11693 has a severity rating of 8.1 (high).
How can CVE-2018-11693 be exploited?
CVE-2018-11693 can be exploited by leveraging an out-of-bounds read in the function Sass::Prelexer::skip_over_scopes, allowing an attacker to disclose information or cause a denial of service.
Which software versions are affected by CVE-2018-11693?
LibSass versions up to and including 3.5.4 are affected by CVE-2018-11693.
Is there a fix for CVE-2018-11693?
LibSass versions after 3.5.4 have addressed the vulnerability and should be updated to mitigate the issue.