Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2017:2939-1

Опубликовано: 07 нояб. 2017
Источник: suse-cvrf

Описание

Security update for libsass

This update for libsass fixes the following DoS vulnerabilities:

  • CVE-2017-11554: Stack consumption vulnerability allowed remote DoS via crafted input (1050148)
  • CVE-2017-11555: Illegal address access in Eval::operator allowed remote DoS via crafted input (boo#1050149)
  • CVE-2017-11556: Stack consumption vulnerability allowed remote DoS via crafted input (boo#1050150)
  • CVE-2017-11605: Heap based buffer over-read allowed remote DoS via crafted input (boo#1050151)
  • CVE-2017-11608: Heap-based buffer over-read allowed remote DoS via crafted input (boo#1050380)

Список пакетов

openSUSE Leap 42.2
libsass-3.3.2-5.1
libsass-3_3_2-0-3.3.2-5.1
libsass-devel-3.3.2-5.1
openSUSE Leap 42.3
libsass-3.3.2-5.1
libsass-3_3_2-0-3.3.2-5.1
libsass-devel-3.3.2-5.1

Описание

There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.


Затронутые продукты
openSUSE Leap 42.2:libsass-3.3.2-5.1
openSUSE Leap 42.2:libsass-3_3_2-0-3.3.2-5.1
openSUSE Leap 42.2:libsass-devel-3.3.2-5.1
openSUSE Leap 42.3:libsass-3.3.2-5.1

Ссылки

Описание

There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.


Затронутые продукты
openSUSE Leap 42.2:libsass-3.3.2-5.1
openSUSE Leap 42.2:libsass-3_3_2-0-3.3.2-5.1
openSUSE Leap 42.2:libsass-devel-3.3.2-5.1
openSUSE Leap 42.3:libsass-3.3.2-5.1

Ссылки

Описание

There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.


Затронутые продукты
openSUSE Leap 42.2:libsass-3.3.2-5.1
openSUSE Leap 42.2:libsass-3_3_2-0-3.3.2-5.1
openSUSE Leap 42.2:libsass-devel-3.3.2-5.1
openSUSE Leap 42.3:libsass-3.3.2-5.1

Ссылки

Описание

There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attack.


Затронутые продукты
openSUSE Leap 42.2:libsass-3.3.2-5.1
openSUSE Leap 42.2:libsass-3_3_2-0-3.3.2-5.1
openSUSE Leap 42.2:libsass-devel-3.3.2-5.1
openSUSE Leap 42.3:libsass-3.3.2-5.1

Ссылки

Описание

There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.


Затронутые продукты
openSUSE Leap 42.2:libsass-3.3.2-5.1
openSUSE Leap 42.2:libsass-3_3_2-0-3.3.2-5.1
openSUSE Leap 42.2:libsass-devel-3.3.2-5.1
openSUSE Leap 42.3:libsass-3.3.2-5.1

Ссылки
Уязвимость openSUSE-SU-2017:2939-1