CVE-2018-19797 PUBLISHED

In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selectors.cpp) may cause a Denial of Service (application crash) via a crafted sass input file.

EPSS 0.25% · 48.1th percentile

Risk Scores

EPSS Score
0.25%
48.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlibsass0, 3.2.5-1, 3.2.5-2
Ubuntu:Pro:18.04:LTSlibsass0, 3.4.3-1, 3.4.6-1

Timeline

References

Open in Interactive Console →