PT-2019-10260 · Sass+2 · Libsass+2
Hongxuchen
·
Published
2019-04-23
·
Updated
2023-02-28
·
CVE-2018-20821
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
LibSass versions 3.5.5 and earlier
Description:
The parsing component in LibSass allows attackers to cause a denial-of-service due to uncontrolled recursion in
Sass::Parser::parse css variable value in parser.cpp.Recommendations:
For LibSass versions 3.5.5 and earlier, consider updating to a version later than 3.5.5 to resolve the issue.
As a temporary workaround, consider restricting the input to the
parse css variable value function to minimize the risk of uncontrolled recursion.Exploit
Fix
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libsass
Suse