Use-after-free in LibSass - CVE-2018-11499
Published: January 5, 2024
Vulnerability identifier: #VU85027
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11499
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in handle_error() function in sass_context.cpp in LibSass. A remote attacker can cause a denial of service (application crash) or possibly unspecified other impact.
Affected software
LibSass
IBM Watson Machine Learning Accelerator
IBM Watson Machine Learning on CP4D
IBM Watson Machine Learning Accelerator
IBM Watson Machine Learning on CP4D
How to mitigate CVE-2018-11499
Install updates from vendor's website.
LibSass - update to 3.5.5
IBM Watson Machine Learning on CP4D - update to 2.6.0
IBM Watson Machine Learning on CP4D - update to 2.6.0