CVE-2018-19219: Buffer Overflow
Published Nov 12, 2018
·Updated
In LibSass 3.5-stable, there is an illegal address access at Sass::Eval::operator that will lead to a DoS attack.
Affected Software
1 affected component
Sass-lang Libsass=3.5.0
Event History
Nov 12, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-19219?
CVE-2018-19219 is a vulnerability in LibSass 3.5-stable that allows for an illegal address access, leading to a denial-of-service (DoS) attack.
2
What is the severity of CVE-2018-19219?
The severity of CVE-2018-19219 is medium, with a CVSS score of 6.5.
3
How does CVE-2018-19219 affect LibSass?
CVE-2018-19219 affects LibSass 3.5-stable.
4
How can CVE-2018-19219 be exploited?
CVE-2018-19219 can be exploited by performing an illegal address access at the Sass::Eval::operator, which can result in a DoS attack.
5
Is there a fix for CVE-2018-19219?
There is currently no known fix for CVE-2018-19219. It is recommended to update to a patched version of LibSass when it becomes available.