CVE-2019-18797: Medium severity libsass vulnerability
Published Nov 6, 2019
·Updated
LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::BinaryExpression) in eval.cpp.
Affected Software
1 affected component
Sass-lang Libsass<3.6.1
Event History
Nov 6, 2019
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-18797.
2
What is the severity of CVE-2019-18797?
The severity of CVE-2019-18797 is medium.
3
What is the affected software for CVE-2019-18797?
The affected software for CVE-2019-18797 is LibSass 3.6.1.
4
How does CVE-2019-18797 work?
CVE-2019-18797 allows for uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.
5
Is there a fix for CVE-2019-18797?
Yes, please refer to the following link for more information on how to fix CVE-2019-18797: https://github.com/sass/libsass/issues/3000.