Heap-based buffer over-read in LibSass - CVE-2018-19839

 

Heap-based buffer over-read in LibSass - CVE-2018-19839

Published: December 4, 2018


Vulnerability identifier: #VU16234
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19839
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition.

The vulnerability exists due to heap-based buffer over-read in the function handle_error in sass_context.cpp. A remote attacker can send a specially crafted sass file, trigger memory corruption and cause the service to crash.


Affected software

LibSass
IBM Edge Application Manager
IBM Planning Analytics Workspace
IBM Security Verify Information Queue
IBM Watson Machine Learning on CP4D
QRadar User Behavior Analytics
IBM QRadar Data Synchronization App

How to mitigate CVE-2018-19839

Update to version 3.5.5.

LibSass - update to 3.5.5
IBM Planning Analytics Workspace - update to 2.0.93
IBM Watson Machine Learning on CP4D - update to 2.6.0
IBM QRadar Data Synchronization App - update to 3.2.1
QRadar User Behavior Analytics - update to 4.1.11
IBM Security Verify Information Queue - update to 10.0.0

External References

Related Security Bulletins