First published: Mon Jan 14 2019(Updated: )
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libsass | =3.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6284 is a vulnerability in LibSass version 3.5.5 that allows for a heap-based buffer over-read in the Sass::Prelexer::alternatives function in prelexer.hpp.
CVE-2019-6284 has a severity score of 6.5, which is considered medium.
LibSass version 3.5.5 is affected by CVE-2019-6284.
To fix CVE-2019-6284, it is recommended to upgrade to a version of LibSass that is not affected by this vulnerability.
You can find more information about CVE-2019-6284 in the following references: [Reference 1](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00047.html), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00051.html), [Reference 3](http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00027.html).