Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20821

Опубликовано: 23 апр. 2019
Источник: debian
EPSS Низкий

Описание

The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsassfixed3.6.3-1package
libsassno-dsabusterpackage
libsassnot-affectedstretchpackage

Примечания

  • https://github.com/sass/libsass/issues/2658

  • Introduced by: https://github.com/sass/libsass/commit/efd97dae376de50b3e6ed724337c4f274a21491d (3.5.0)

  • Fixed by: https://github.com/sass/libsass/commit/f2db04883e5fff4e03777dcc1eb60d4373c45be1

EPSS

Процентиль: 54%
0.00316
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).

CVSS3: 7.5
redhat
больше 7 лет назад

The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).

CVSS3: 6.5
nvd
почти 7 лет назад

The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).

CVSS3: 6.5
github
больше 3 лет назад

The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).

suse-cvrf
больше 6 лет назад

Security update for libsass

EPSS

Процентиль: 54%
0.00316
Низкий