AVG-359 log
Package | libsass |
Status | Fixed |
Severity | High |
Type | denial of service |
Affected | 3.4.9-1 |
Fixed | 3.5.4-1 |
Current | 3.6.6-1 [extra] |
Ticket | None |
Created | Mon Jul 24 15:39:54 2017 |
Issue | Severity | Remote | Type | Description |
---|---|---|---|---|
CVE-2017-11608 | High | Yes | Denial of service | There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote... |
CVE-2017-11605 | High | Yes | Denial of service | There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attack. |
CVE-2017-11555 | Medium | Yes | Denial of service | There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service. |
CVE-2017-11554 | Medium | Yes | Denial of service | There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote... |
Notes |
---|
Apparently most of these have been fixed in 3.5.0.. |