CVE-2018-19827: Use After Free
In LibSass 3.5.5, a use-after-free vulnerability exists in the SharedPtr class in SharedPtr.cpp (or SharedPtr.hpp) that may cause a denial of service (application crash) or possibly have unspecified other impact.
Other sources
Libsass is vulnerable to a denial of service, caused by a use after free in the SharedPtr class in SharedPtr.cpp. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19827?
CVE-2018-19827 is a use-after-free vulnerability in LibSass 3.5.5 that may cause a denial of service or have other unspecified impacts.
How severe is CVE-2018-19827?
CVE-2018-19827 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2018-19827?
LibSass 3.5.5 is affected by CVE-2018-19827.
How can CVE-2018-19827 be exploited?
CVE-2018-19827 can be exploited by triggering a use-after-free vulnerability in the SharedPtr class in LibSass.
Are there any patches or fixes available for CVE-2018-19827?
It is recommended to update to a version of LibSass that is not affected by CVE-2018-19827.