CVE-2018-20190: Null Pointer Dereference
In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Eval::operator()(Sass::SupportsOperator) in eval.cpp may cause a Denial of Service (application crash) via a crafted sass input file.
Other sources
LibSass is vulnerable to a denial of service, caused by a NULL pointer dereference in the function Sass::Eval::operator() in eval.cpp. By using a specially crafted sass input file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-20190?
CVE-2018-20190 is a vulnerability in LibSass 3.5.5 that may cause a Denial of Service (application crash) via a crafted sass input file.
How severe is CVE-2018-20190?
CVE-2018-20190 has a severity score of 6.5 (medium).
How does CVE-2018-20190 affect LibSass?
CVE-2018-20190 affects LibSass version 3.5.5.
How can CVE-2018-20190 be exploited?
CVE-2018-20190 can be exploited by providing a crafted sass input file.
Is there a fix for CVE-2018-20190?
Yes, updating to a version higher than 3.5.5 resolves the vulnerability.