7.5
CVSSv2

CVE-2018-11499

Published: 26/05/2018 Updated: 23/07/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x up to and including 3.5.4 that could be leveraged to cause a denial of service (application crash) or possibly unspecified other impact.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sass-lang libsass

Vendor Advisories

Debian Bug report logs - #900182 libsass: CVE-2018-11499: heap use-after-free Package: src:libsass; Maintainer for src:libsass is Debian Sass team <pkg-sass-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 27 May 2018 08:54:02 UTC Severity: important Tags: fixed-upstrea ...