Stack-based buffer overflow in LibSass - CVE-2018-19837
Published: December 4, 2018 / Updated: December 4, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition.
The vulnerability exists due to stack-based buffer overflow in Sass::Eval::operator()(Sass::Binary_Expression*) inside eval.cpp when incorrect parsing of '%' as a modulo operator in parser.cpp. A remote attacker can send a specially crafted sass file, trigger memory corruption and cause the service to crash.
Affected software
IBM Watson Machine Learning on CP4D
How to mitigate CVE-2018-19837
IBM Watson Machine Learning on CP4D - update to 2.6.0