CVE-2018-19797: Null Pointer Dereference
In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::SelectorList::populateextends in SharedPtr.hpp (used by ast.cpp and astselectors.cpp) may cause a Denial of Service (application crash) via a crafted sass input file.
Other sources
LibSass is vulnerable to a denial of service, caused by a NULL pointer dereference in the function Sass::SelectorList::populateextends in SharedPtr.hpp. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-19797.
What is the severity level of CVE-2018-19797?
The severity level of CVE-2018-19797 is medium, with a severity value of 6.5.
What is the affected software?
The affected software is LibSass version 3.5.5.
What can an attacker do with this vulnerability?
An attacker can cause a Denial of Service by crashing the application using a crafted sass input file.
How can I fix CVE-2018-19797?
To fix CVE-2018-19797, you should update LibSass to a version that is not affected.