CVE-2018-19839: Medium severity libsass vulnerability
In LibSass prior to 3.5.5, the function handleerror in sasscontext.cpp allows attackers to cause a denial-of-service resulting from a heap-based buffer over-read via a crafted sass file.
Other sources
LibSass is vulnerable to a denial of service, caused by a heap-based buffer over-read in the handleerror function in sasscontext.cpp. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-19839?
CVE-2018-19839 is a vulnerability in LibSass prior to version 3.5.5 that allows attackers to cause a denial-of-service by exploiting a heap-based buffer over-read.
What is the severity of CVE-2018-19839?
The severity of CVE-2018-19839 is medium, with a severity score of 6.5.
How does CVE-2018-19839 affect LibSass?
CVE-2018-19839 affects LibSass versions prior to 3.5.5.
How can attackers exploit CVE-2018-19839?
Attackers can exploit CVE-2018-19839 by crafting a malicious sass file that triggers a heap-based buffer over-read.
Is there a fix for CVE-2018-19839?
Yes, the fix for CVE-2018-19839 is to upgrade LibSass to version 3.5.5 or newer.