In LibSass prima 3.5.5, funzioni all’interno ast.cpp di espansione IMPLEMENT_AST_OPERATORS permettono aggressori di provocare una negazione del servizio risultante dal consumo pila tramite un file sass predisposto, come dimostrato dalle chiamate ricorsive coinvolgono clone (), cloneChildren (), e copy (). |
https://github.com/sass/libsass/issues/2660 http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00047.html http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00051.html http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00027.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19838 |
Vulnerabilità: CVE-2018-19838
