Out-of-bounds read in LibSass - CVE-2018-11697
Published: May 29, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists in the function Sass::Prelexer::exactly(). A remote attacker can create a specially crafted file, trick the victim into opening it, trigger an out-of-bounds read error and disclose information or manipulated to read from unmapped memory causing a denial of service.
Affected software
IBM Watson Machine Learning Accelerator
IBM Security Verify Information Queue
IBM Watson Machine Learning on CP4D
How to mitigate CVE-2018-11697
IBM Watson Machine Learning on CP4D - update to 2.6.0
IBM Security Verify Information Queue - update to 10.0.0