#VU16232 Stack-based buffer overflow in LibSass - CVE-2018-19837
Published: December 4, 2018 / Updated: December 4, 2018
LibSass
Sass
Description
The vulnerability allows a remote attacker to cause DoS condition.
The vulnerability exists due to stack-based buffer overflow in Sass::Eval::operator()(Sass::Binary_Expression*) inside eval.cpp when incorrect parsing of '%' as a modulo operator in parser.cpp. A remote attacker can send a specially crafted sass file, trigger memory corruption and cause the service to crash.