Bug ID 1096660
Summary VUL-0: CVE-2018-11697: libsass: Heap buffer over-read in Sass::Prelexer::exactly in lexer.hpp
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/207112/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee crrodriguez@opensuse.org
Reporter abergmann@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

rh#1588663

An issue was discovered in LibSaas through 3.5.4. An out-of-bounds read of a
memory region was found in the function Sass::Prelexer::exactly() which could
be
leveraged by an attacker to disclose information or manipulated to read from
unmapped memory causing a denial of service.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1588663
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-11697
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-11697.html
https://github.com/sass/libsass/issues/2656


You are receiving this mail because: