CVE-2018-19837: Medium severity libsass vulnerability
Published Dec 4, 2018
·Updated
In LibSass prior to 3.5.5, Sass::Eval::operator()(Sass::BinaryExpression) inside eval.cpp allows attackers to cause a denial-of-service resulting from stack consumption via a crafted sass file, because of certain incorrect parsing of '%' as a modulo operator in parser.cpp.
Affected Software
1 affected component
Sass-lang Libsass<3.5.5
Remediation
Patch Available
Event History
Dec 4, 2018
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-19837.
2
What is the severity of CVE-2018-19837?
The severity of CVE-2018-19837 is medium with a CVSS score of 6.5.
3
What software is affected by CVE-2018-19837?
The Sass-lang Libsass software with versions up to and excluding 3.5.5 is affected by CVE-2018-19837.
4
How can an attacker exploit CVE-2018-19837?
An attacker can exploit CVE-2018-19837 by using a crafted sass file that triggers a denial-of-service due to stack consumption.
5
Is there a fix available for CVE-2018-19837?
Yes, updating the Sass-lang Libsass software to version 3.5.5 or newer fixes CVE-2018-19837.