First published: Mon Jun 04 2018(Updated: )
An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Inspect::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libsass | <=3.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2018-11696.
The severity of CVE-2018-11696 is high with a severity value of 8.8.
The affected software of CVE-2018-11696 is LibSass version 3.5.4.
CVE-2018-11696 could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
Yes, updating to a version of LibSass that is not affected by the vulnerability will fix CVE-2018-11696.