CVE-2018-11694: Null Pointer Dereference
An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::selectorappend which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
Other sources
LibSaas is vulnerable to a denial of service, caused by a NULL pointer dereference in the function Sass::Functions::selectorappend. By using a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-11694.
What is the severity level of CVE-2018-11694?
The severity level of CVE-2018-11694 is high.
What software versions are affected by CVE-2018-11694?
Versions up to and including 3.5.4 of Sass-lang Libsass are affected by CVE-2018-11694.
What is the impact of CVE-2018-11694?
CVE-2018-11694 can cause a denial of service (application crash) or possibly have unspecified other impact.
Is there a fix available for CVE-2018-11694?
Yes, a fix for CVE-2018-11694 is available. It is recommended to update to a version beyond 3.5.4 of Sass-lang Libsass.