First published: Mon Jun 04 2018(Updated: )
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::exactly() which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libsass | <=3.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-11697.
The severity of CVE-2018-11697 is high (8.1).
The affected software is LibSass up to version 3.5.4.
CVE-2018-11697 is an out-of-bounds read vulnerability in LibSass through 3.5.4, which could be exploited to disclose information or cause a denial of service.
Yes, you can find more information about CVE-2018-11697 at https://github.com/sass/libsass/issues/2656.