PT-2019-10260 · Sass+2 · Libsass+2
Hongxuchen
·
Publicado
2019-04-23
·
Atualizado
2023-02-28
·
CVE-2018-20821
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
LibSass versions 3.5.5 and earlier
Description:
The parsing component in LibSass allows attackers to cause a denial-of-service due to uncontrolled recursion in
Sass::Parser::parse css variable value in parser.cpp.Recommendations:
For LibSass versions 3.5.5 and earlier, consider updating to a version later than 3.5.5 to resolve the issue.
As a temporary workaround, consider restricting the input to the
parse css variable value function to minimize the risk of uncontrolled recursion.Exploit
Correção
DoS
Uncontrolled Recursion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Libsass
Suse