CVE-2018-11696: Null Pointer Dereference
Published Jun 4, 2018
·Updated
An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Inspect::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
Affected Software
1 affected component
Sass-lang Libsass<=3.5.4
Remediation
Patch Available
Event History
Jun 4, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-11696.
2
What is the severity of CVE-2018-11696?
The severity of CVE-2018-11696 is high with a severity value of 8.8.
3
What is the affected software of CVE-2018-11696?
The affected software of CVE-2018-11696 is LibSass version 3.5.4.
4
What is the impact of CVE-2018-11696?
CVE-2018-11696 could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
5
Is there a fix available for CVE-2018-11696?
Yes, updating to a version of LibSass that is not affected by the vulnerability will fix CVE-2018-11696.