Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-19839

Опубликовано: 04 дек. 2018
Источник: debian
EPSS Низкий

Описание

In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service resulting from a heap-based buffer over-read via a crafted sass file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsassfixed3.5.5-4package
libsassno-dsastretchpackage

Примечания

  • https://github.com/sass/libsass/issues/2657

  • https://github.com/sass/libsass/pull/2767

EPSS

Процентиль: 47%
0.00241
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 7 лет назад

In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service resulting from a heap-based buffer over-read via a crafted sass file.

CVSS3: 3.3
redhat
больше 7 лет назад

In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service resulting from a heap-based buffer over-read via a crafted sass file.

CVSS3: 6.5
nvd
около 7 лет назад

In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service resulting from a heap-based buffer over-read via a crafted sass file.

CVSS3: 6.5
github
больше 3 лет назад

In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service resulting from a heap-based buffer over-read via a crafted sass file.

suse-cvrf
больше 6 лет назад

Security update for libsass

EPSS

Процентиль: 47%
0.00241
Низкий