CVE-2017-11555
published 2017-07-23CVE-2017-11555: There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
PriorityP434high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.20%
64.7th percentile
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsass | < libsass 3.5.4-1 (bookworm) | libsass 3.5.4-1 (bookworm) |
| libsass | libsass | — | — |
| libsass | libsass | >= 0 < 3.5.4-1 | 3.5.4-1 |
| libsass | libsass | >= 0 < 3.5.4-1 | 3.5.4-1 |
| libsass | libsass | >= 0 < 3.5.4-1 | 3.5.4-1 |
| libsass | libsass | >= 0 < 3.5.4-1 | 3.5.4-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qqp3-5fc5-8mf5: There is an illegal address access in Sass::Eval::operator() in eval
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2017-12963 [HIGH] CWE-125 GHSA-qqp3-5fc5-8mf5: There is an illegal address access in Sass::Eval::operator() in eval
There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this is similar to CVE-2017-11555 but remains exploitable after the vendor's CVE-2017-11555 fix (available from GitHub after 2017-07-24).
GHSA
GHSA-38c9-9r7r-r27j: There is an illegal address access in the Eval::operator function in eval
ghsa_unreviewed·2022-05-17
CVE-2017-11555 [HIGH] CWE-20 GHSA-38c9-9r7r-r27j: There is an illegal address access in the Eval::operator function in eval
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
OSV
CVE-2017-12963: There is an illegal address access in Sass::Eval::operator() in eval
osv·2017-08-18·CVSS 7.5
CVE-2017-12963 [HIGH] CVE-2017-12963: There is an illegal address access in Sass::Eval::operator() in eval
There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this is similar to CVE-2017-11555 but remains exploitable after the vendor's CVE-2017-11555 fix (available from GitHub after 2017-07-24).
OSV
CVE-2017-11555: There is an illegal address access in the Eval::operator function in eval
osv·2017-07-23·CVSS 7.5
CVE-2017-11555 [HIGH] CVE-2017-11555: There is an illegal address access in the Eval::operator function in eval
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Debian
CVE-2017-11555: libsass - There is an illegal address access in the Eval::operator function in eval.cpp in...
vendor_debian·2017·CVSS 7.5
CVE-2017-11555 [HIGH] CVE-2017-11555: libsass - There is an illegal address access in the Eval::operator function in eval.cpp in...
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Scope: local
bookworm: resolved (fixed in 3.5.4-1)
bullseye: resolved (fixed in 3.5.4-1)
forky: resolved (fixed in 3.5.4-1)
sid: resolved (fixed in 3.5.4-1)
trixie: resolved (fixed in 3.5.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 libsass: Multiple vulnerabilities [epel-7]
bugzilla·2017-07-25·CVSS 7.5
CVE-2017-11554 [HIGH] CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 libsass: Multiple vulnerabilities [epel-7]
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 libsass: Multiple vulnerabilities [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use
Bugzilla
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 CVE-2017-12962 CVE-2017-12963 CVE-2017-12964 libsass: Multiple vulnerabilities
bugzilla·2017-07-25·CVSS 7.5
CVE-2017-11554 [HIGH] CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 CVE-2017-12962 CVE-2017-12963 CVE-2017-12964 libsass: Multiple vulnerabilities
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 CVE-2017-12962 CVE-2017-12963 CVE-2017-12964 libsass: Multiple vulnerabilities
Multiple security issues were found in libsass.
CVE-2017-11554
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
https://bugzilla.redhat.com/show_bug.cgi?id=1471780
https://github.com/sass/libsass/issues/2445
CVE-2017-11555
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
https://bugzilla.redhat.com/show_bug.cgi?id=1471782
CVE-2017-11556
There is a stack consumption vulnerability in the Parser::advanceToNextT
2017-07-23
Published