CVE-2019-18799: Null Pointer Dereference
Published Nov 6, 2019
·Updated
LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parserselectors.cpp.
Affected Software
1 affected component
Sass-lang Libsass<3.6.3
Event History
Nov 6, 2019
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
Description
Frequently Asked Questions
1
What is CVE-2019-18799?
CVE-2019-18799 is a vulnerability in LibSass before version 3.6.3 that allows a NULL pointer dereference in the parseCompoundSelector function.
2
How severe is CVE-2019-18799?
CVE-2019-18799 has a severity level of medium, with a CVSS score of 6.5.
3
What is the affected software for CVE-2019-18799?
The affected software for CVE-2019-18799 is LibSass version up to and exclusive of 3.6.3.
4
How can I fix CVE-2019-18799?
To fix CVE-2019-18799, you should update LibSass to version 3.6.3 or newer.
5
Where can I find more information about CVE-2019-18799?
More information about CVE-2019-18799 can be found at the following link: [https://github.com/sass/libsass/issues/3001](https://github.com/sass/libsass/issues/3001)