CVE-2019-6286: Medium severity libsass vulnerability
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skipoverscopes in prelexer.hpp when called from Sass::Parser::parseimport(), a similar issue to CVE-2018-11693.
Other sources
LibSass is vulnerable to a denial of service, caused by a heap-based buffer over-read in Sass::Prelexer::skipoverscopes in prelexer.hpp. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6286?
CVE-2019-6286 is a vulnerability in LibSass 3.5.5.
How does CVE-2019-6286 affect Sass-lang Libsass?
CVE-2019-6286 affects Sass-lang Libsass version 3.5.5.
What is the severity of CVE-2019-6286?
CVE-2019-6286 has a severity rating of 6.5 (medium).
How can I fix CVE-2019-6286 in LibSass?
To fix CVE-2019-6286, update to a version of LibSass that is not affected by the vulnerability.
Is there any additional information about CVE-2019-6286?
For additional information about CVE-2019-6286, you can refer to the provided references.