CVE-2018-19218: Medium severity Sass-lang Libsass vulnerability
Published Nov 12, 2018
·Updated
In LibSass 3.5-stable, there is an illegal address access at Sass::Parser::parsecssvariablevaluetoken that will lead to a DoS attack.
Affected Software
1 affected component
Sass-lang Libsass=3.5.0
Event History
Nov 12, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-19218?
CVE-2018-19218 is a vulnerability in LibSass 3.5-stable that allows for an illegal address access, leading to a Denial of Service (DoS) attack.
2
How severe is CVE-2018-19218?
CVE-2018-19218 has a severity rating of 6.5, which is considered medium.
3
Which LibSass version is affected by CVE-2018-19218?
LibSass 3.5.0 is affected by CVE-2018-19218.
4
How can I fix CVE-2018-19218?
There is currently no known fix for CVE-2018-19218. It is recommended to update to a version of LibSass that is not affected by this vulnerability when it becomes available.
5
Where can I find more information about CVE-2018-19218?
You can find more information about CVE-2018-19218 at the following reference: https://bugzilla.redhat.com/show_bug.cgi?id=1643758