AVG-359 log
| Package | libsass |
| Status | Fixed |
| Severity | High |
| Type | denial of service |
| Affected | 3.4.9-1 |
| Fixed | 3.5.4-1 |
| Current | 3.6.6-1 [extra] |
| Ticket | None |
| Created | Mon Jul 24 15:39:54 2017 |
| Issue | Severity | Remote | Type | Description |
|---|---|---|---|---|
| CVE-2017-11608 | High | Yes | Denial of service | There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote... |
| CVE-2017-11605 | High | Yes | Denial of service | There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attack. |
| CVE-2017-11555 | Medium | Yes | Denial of service | There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service. |
| CVE-2017-11554 | Medium | Yes | Denial of service | There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote... |
| Notes |
|---|
Apparently most of these have been fixed in 3.5.0.. |