CVE-2017-11556
published 2017-07-23CVE-2017-11556: There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial…
PriorityP432high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.20%
64.7th percentile
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsass | < libsass 3.5.4-1 (bookworm) | libsass 3.5.4-1 (bookworm) |
| libsass | libsass | — | — |
| libsass | libsass | >= 0 < 3.5.4-1 | 3.5.4-1 |
| libsass | libsass | >= 0 < 3.5.4-1 | 3.5.4-1 |
| libsass | libsass | >= 0 < 3.5.4-1 | 3.5.4-1 |
| libsass | libsass | >= 0 < 3.5.4-1 | 3.5.4-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-11556: libsass - There is a stack consumption vulnerability in the Parser::advanceToNextToken fun...
vendor_debian·2017·CVSS 7.5
CVE-2017-11556 [HIGH] CVE-2017-11556: libsass - There is a stack consumption vulnerability in the Parser::advanceToNextToken fun...
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
Scope: local
bookworm: resolved (fixed in 3.5.4-1)
bullseye: resolved (fixed in 3.5.4-1)
forky: resolved (fixed in 3.5.4-1)
sid: resolved (fixed in 3.5.4-1)
trixie: resolved (fixed in 3.5.4-1)
GHSA
GHSA-x2cj-w5c5-j878: There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser
ghsa_unreviewed·2022-05-13
CVE-2017-11556 [HIGH] CWE-674 GHSA-x2cj-w5c5-j878: There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
OSV
CVE-2017-11556: There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser
osv·2017-07-23·CVSS 7.5
CVE-2017-11556 [HIGH] CVE-2017-11556: There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 libsass: Multiple vulnerabilities [epel-7]
bugzilla·2017-07-25·CVSS 7.5
CVE-2017-11554 [HIGH] CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 libsass: Multiple vulnerabilities [epel-7]
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 libsass: Multiple vulnerabilities [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use
Bugzilla
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 CVE-2017-12962 CVE-2017-12963 CVE-2017-12964 libsass: Multiple vulnerabilities
bugzilla·2017-07-25·CVSS 7.5
CVE-2017-11554 [HIGH] CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 CVE-2017-12962 CVE-2017-12963 CVE-2017-12964 libsass: Multiple vulnerabilities
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 CVE-2017-12962 CVE-2017-12963 CVE-2017-12964 libsass: Multiple vulnerabilities
Multiple security issues were found in libsass.
CVE-2017-11554
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
https://bugzilla.redhat.com/show_bug.cgi?id=1471780
https://github.com/sass/libsass/issues/2445
CVE-2017-11555
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
https://bugzilla.redhat.com/show_bug.cgi?id=1471782
CVE-2017-11556
There is a stack consumption vulnerability in the Parser::advanceToNextT
2017-07-23
Published