CVE-2019-6283: Medium severity libsass vulnerability
Published Jan 14, 2019
·Updated
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthesescope in prelexer.hpp.
Other sources
LibSass is vulnerable to a denial of service, caused by a heap-based buffer over-read in Sass::Prelexer::parenthesescope in prelexer.hpp. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
7 affected components
Sass-lang Libsass=3.5.5
IBM Data Virtualization on Cloud Pak for Data<=3.0
IBM Watson Query on Cloud Pak for Data<=2.2
IBM Watson Query on Cloud Pak for Data<=2.1
IBM Watson Query on Cloud Pak for Data<=2.0
IBM Data Virtualization on Cloud Pak for Data<=1.8
IBM Data Virtualization on Cloud Pak for Data<=1.7
Event History
Jan 14, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Aug 15, 2025
Data Sourced
via IBM·03:29 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-6283?
CVE-2019-6283 is a vulnerability in LibSass 3.5.5 that allows a heap-based buffer over-read.
2
What is the severity of CVE-2019-6283?
The severity of CVE-2019-6283 is medium (6.5).
3
How does CVE-2019-6283 affect LibSass?
CVE-2019-6283 affects LibSass version 3.5.5.
4
How can I fix CVE-2019-6283?
To fix CVE-2019-6283, update LibSass to a version that is not affected by the vulnerability.
5
What is the CVE ID for LibSass's heap-based buffer over-read vulnerability?
The CVE ID for LibSass's heap-based buffer over-read vulnerability is CVE-2019-6283.