NULL pointer dereference in LibSass - CVE-2018-11694

 

NULL pointer dereference in LibSass - CVE-2018-11694

Published: June 5, 2023


Vulnerability identifier: #VU76836
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11694
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the function Sass::Functions::selector_append. A remote attacker can trick the victim into opening specially crafted data and perform a denial of service (DoS) attack.


Affected software

LibSass
IBM Watson Machine Learning Accelerator
IBM Planning Analytics Workspace
IBM Edge Application Manager
IBM Watson Machine Learning on CP4D
QRadar User Behavior Analytics
IBM QRadar Data Synchronization App

How to mitigate CVE-2018-11694

Install updates from vendor's website.

IBM Planning Analytics Workspace - update to 2.0.93
IBM Watson Machine Learning on CP4D - update to 2.6.0
IBM QRadar Data Synchronization App - update to 3.2.1
QRadar User Behavior Analytics - update to 4.1.11

External References

Related Security Bulletins