ZeroHour

CVE-2018-19218

PoC
CVSS 3.0
6.5 medium
EPSS
1%p65
Published
()
Modified
Description

In LibSass 3.5-stable, there is an illegal address access at Sass::Parser::parse_css_variable_value_token that will lead to a DoS attack.

Vendors
sass-lang
Products
libsass
Weakness
CWE-125
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.