CVE-2018-11695: Null Pointer Dereference
Published Jun 4, 2018
·Updated
An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
Affected Software
1 affected component
Sass-lang Libsass<=3.5.2
Remediation
Patch Available
Event History
Jun 4, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability identifier for this issue?
The vulnerability identifier for this issue is CVE-2018-11695.
2
What is the severity of CVE-2018-11695?
The severity of CVE-2018-11695 is high with a CVSS score of 8.8.
3
What is the affected software?
The affected software is LibSass version up to and including 3.5.2.
4
What is the impact of this vulnerability?
This vulnerability can cause a denial of service (application crash) or potentially have other unspecified impacts.
5
How can I fix CVE-2018-11695?
To fix CVE-2018-11695, update LibSass to version 3.5.3 or later.