Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Xzyfer

#29879of 53,624
8.8Total CVSS
Vulnerabilities · 1
PT-2018-10755
8.8
2018-06-04
Sass · Libsass · CVE-2018-11695
**Name of the Vulnerable Software and Affected Versions** LibSass versions prior to 3.5.3 **Description** A NULL pointer dereference was found in the `Sass::Expand::operator` function, which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact. **Recommendations** For versions prior to 3.5.3, update to version 3.5.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the `Sass::Expand::operator` function until a patch is available.