CVE-2018-11697: High severity libsass vulnerability
Published Jun 4, 2018
·Updated
An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::exactly() which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
Affected Software
1 affected component
Sass-lang Libsass<=3.5.4
Remediation
Patch Available
Event History
Jun 4, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-11697.
2
What is the severity of CVE-2018-11697?
The severity of CVE-2018-11697 is high (8.1).
3
What is the affected software?
The affected software is LibSass up to version 3.5.4.
4
What is the CVE description for CVE-2018-11697?
CVE-2018-11697 is an out-of-bounds read vulnerability in LibSass through 3.5.4, which could be exploited to disclose information or cause a denial of service.
5
Is there any reference available for CVE-2018-11697?
Yes, you can find more information about CVE-2018-11697 at https://github.com/sass/libsass/issues/2656.