CVE-2017-11608
published 2017-07-24CVE-2017-11608: There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial…
PriorityP424medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.15%
63.0th percentile
There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsass | < libsass 3.4.6-1 (bookworm) | libsass 3.4.6-1 (bookworm) |
| libsass | libsass | — | — |
| libsass | libsass | >= 0 < 3.4.6-1 | 3.4.6-1 |
| libsass | libsass | >= 0 < 3.4.6-1 | 3.4.6-1 |
| libsass | libsass | >= 0 < 3.4.6-1 | 3.4.6-1 |
| libsass | libsass | >= 0 < 3.4.6-1 | 3.4.6-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-11608: libsass - There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak funct...
vendor_debian·2017·CVSS 6.5
CVE-2017-11608 [MEDIUM] CVE-2017-11608: libsass - There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak funct...
There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 3.4.6-1)
bullseye: resolved (fixed in 3.4.6-1)
forky: resolved (fixed in 3.4.6-1)
sid: resolved (fixed in 3.4.6-1)
trixie: resolved (fixed in 3.4.6-1)
GHSA
GHSA-5cqh-5hxx-9w4g: There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer
ghsa_unreviewed·2022-05-13
CVE-2017-11608 [MEDIUM] CWE-125 GHSA-5cqh-5hxx-9w4g: There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer
There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
OSV
CVE-2017-11608: There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer
osv·2017-07-24·CVSS 6.5
CVE-2017-11608 [MEDIUM] CVE-2017-11608: There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer
There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 libsass: Multiple vulnerabilities [epel-7]
bugzilla·2017-07-25·CVSS 7.5
CVE-2017-11554 [HIGH] CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 libsass: Multiple vulnerabilities [epel-7]
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 libsass: Multiple vulnerabilities [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use
Bugzilla
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 CVE-2017-12962 CVE-2017-12963 CVE-2017-12964 libsass: Multiple vulnerabilities
bugzilla·2017-07-25·CVSS 7.5
CVE-2017-11554 [HIGH] CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 CVE-2017-12962 CVE-2017-12963 CVE-2017-12964 libsass: Multiple vulnerabilities
CVE-2017-11554 CVE-2017-11555 CVE-2017-11556 CVE-2017-11605 CVE-2017-11608 CVE-2017-12962 CVE-2017-12963 CVE-2017-12964 libsass: Multiple vulnerabilities
Multiple security issues were found in libsass.
CVE-2017-11554
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
https://bugzilla.redhat.com/show_bug.cgi?id=1471780
https://github.com/sass/libsass/issues/2445
CVE-2017-11555
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
https://bugzilla.redhat.com/show_bug.cgi?id=1471782
CVE-2017-11556
There is a stack consumption vulnerability in the Parser::advanceToNextT
2017-07-24
Published