CVE-2018-19838: Medium severity libsass vulnerability
Published Dec 4, 2018
·Updated
In LibSass prior to 3.5.5, functions inside ast.cpp for IMPLEMENTASTOPERATORS expansion allow attackers to cause a denial-of-service resulting from stack consumption via a crafted sass file, as demonstrated by recursive calls involving clone(), cloneChildren(), and copy().
Affected Software
1 affected component
Sass-lang Libsass<3.5.5
Event History
Dec 4, 2018
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-19838.
2
What is the severity of CVE-2018-19838?
The severity of CVE-2018-19838 is medium with a severity value of 6.5.
3
What is the affected software for CVE-2018-19838?
The affected software for CVE-2018-19838 is LibSass prior to version 3.5.5.
4
How can attackers exploit CVE-2018-19838?
Attackers can exploit CVE-2018-19838 by causing a denial-of-service resulting from stack consumption via a crafted Sass file.
5
Is there a fix available for CVE-2018-19838?
Yes, a fix is available for CVE-2018-19838 in LibSass version 3.5.5.