CVE-2018-11693Out-of-bounds Read in Libsass

CWE-125Out-of-bounds Read14 documents7 sources
Severity
8.1HIGHNVD
NVD6.5
EPSS
0.4%
top 40.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 4
Latest updateMay 14

Description

An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::skip_over_scopes which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages3 packages

debiandebian/libsass< libsass 3.5.4+20180621~c0a6cf3-1 (bookworm)+1
Debianlibsass/libsass< 3.5.5-3+7
NVDsass-lang/libsass3.5.4+1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-rm2q-7xhq-fcm2: An issue was discovered in LibSass through 32022-05-14
GHSA
GHSA-v472-248w-rwx2: In LibSass 32022-05-14
OSV
CVE-2019-6286: In LibSass 32019-01-14
OSV
CVE-2018-11693: An issue was discovered in LibSass through 32018-06-04

📋Vendor Advisories

4
Ubuntu
LibSass vulnerabilities2021-03-15
Red Hat
libsass: heap-based buffer over-read in Sass::Prelexer::skip_over_scopes in prelexer.hpp2019-01-14
Debian
CVE-2019-6286: libsass - In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_o...2019
Debian
CVE-2018-11693: libsass - An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a mem...2018

💬Community

4
Bugzilla
CVE-2019-6286 libsass: heap-based buffer over-read in Sass::Prelexer::skip_over_scopes in prelexer.hpp2019-01-23
Bugzilla
CVE-2018-11693 libsass: Heap buffer over read in function Sass::Prelexer::skip_over_scopes in prelexer.hpp [epel-7]2018-06-07
Bugzilla
CVE-2018-11693 libsass: Heap buffer over read in function Sass::Prelexer::skip_over_scopes in prelexer.hpp2018-06-07
Bugzilla
CVE-2018-11693 libsass: Heap buffer over read in function Sass::Prelexer::skip_over_scopes in prelexer.hpp [fedora-all]2018-06-07