First published: Wed Nov 06 2019(Updated: )
LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libsass | <3.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18799 is a vulnerability in LibSass before version 3.6.3 that allows a NULL pointer dereference in the parseCompoundSelector function.
CVE-2019-18799 has a severity level of medium, with a CVSS score of 6.5.
The affected software for CVE-2019-18799 is LibSass version up to and exclusive of 3.6.3.
To fix CVE-2019-18799, you should update LibSass to version 3.6.3 or newer.
More information about CVE-2019-18799 can be found at the following link: [https://github.com/sass/libsass/issues/3001](https://github.com/sass/libsass/issues/3001)