First published: Wed Nov 06 2019(Updated: )
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libsass | <3.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18798 is a vulnerability in LibSass before version 3.6.3 that allows a heap-based buffer over-read.
The severity of CVE-2019-18798 is medium with a CVSS severity score of 6.5.
CVE-2019-18798 affects LibSass versions up to and excluding 3.6.3.
To fix CVE-2019-18798, update LibSass to version 3.6.3 or later.
You can find more information about CVE-2019-18798 at the following link: [GitHub Issue](https://github.com/sass/libsass/issues/2999)