In LibSass prior to 3.5.5, Sass::Eval::operator()(Sass::Binary_Expression*) inside eval.cpp allows attackers to cause a denial-of-service resulting from stack consumption via a crafted sass file, because of certain incorrect parsing of '%' as a modulo operator in parser.cpp.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-11512 In LibSass prior to 3.5.5, Sass::Eval::operator()(Sass::Binary_Expression*) inside eval.cpp allows attackers to cause a denial-of-service resulting from stack consumption via a crafted sass file, because of certain incorrect parsing of '%' as a modulo operator in parser.cpp.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T11:44:20.721Z

Reserved: 2018-12-03T00:00:00

Link: CVE-2018-19837

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-12-04T09:29:00.320

Modified: 2024-11-21T03:58:39.693

Link: CVE-2018-19837

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses