CVE-2019-18798: Medium severity libsass vulnerability
Published Nov 6, 2019
·Updated
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in astselweave.cpp.
Affected Software
1 affected component
Sass-lang Libsass<3.6.3
Event History
Nov 6, 2019
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
Description
Frequently Asked Questions
1
What is CVE-2019-18798?
CVE-2019-18798 is a vulnerability in LibSass before version 3.6.3 that allows a heap-based buffer over-read.
2
What is the severity of CVE-2019-18798?
The severity of CVE-2019-18798 is medium with a CVSS severity score of 6.5.
3
How does CVE-2019-18798 affect LibSass?
CVE-2019-18798 affects LibSass versions up to and excluding 3.6.3.
4
How can I fix CVE-2019-18798?
To fix CVE-2019-18798, update LibSass to version 3.6.3 or later.
5
Where can I find more information about CVE-2019-18798?
You can find more information about CVE-2019-18798 at the following link: [GitHub Issue](https://github.com/sass/libsass/issues/2999)