First published: Mon Dec 03 2018(Updated: )
** DISPUTED ** In inspect.cpp in LibSass 3.5.5, a high memory footprint caused by an endless loop (containing a Sass::Inspect::operator()(Sass::String_Quoted*) stack frame) may cause a Denial of Service via crafted sass input files with stray '&' or '/' characters. NOTE: Upstream comments indicate this issue is closed as "won't fix" and "works as intended" by design.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libsass | =3.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19826 is a vulnerability in LibSass 3.5.5 that can cause a Denial of Service via crafted sass input files with stray '&' or '/' characters.
The severity of CVE-2018-19826 is medium (6.5).
CVE-2018-19826 affects LibSass 3.5.5.
To fix the CVE-2018-19826 vulnerability, update to a version of LibSass that is not affected by this issue.
For more information about CVE-2018-19826, refer to the GitHub issue linked in the references.