Skip to main content

Out-of-bounds Read in github.com/wellington/go-libsass

CVE-2019-6284

  • github.com/wellington/go-libsass
  • io.bit3:jsass
  • libsass
  • libsassnet
  • libsassnet.Web
  • node-sass
  • org.webjars.bower:sass.js
  • org.webjars.npm:node-sass
  • sassc
  • sass.js
Severity Medium
Score 6.5/10

Summary

In libsass package versions prior to 3.6.0, a Heap-based Buffer Overread vulnerability exists in "Sass::Prelexer::alternatives" in "prelexer.hpp".

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • REQUIRED
  • NONE
  • NONE
  • HIGH

CWE-125 - Out-of-Bounds Read

Out-of-bounds read is a vulnerability that allows access to memory beyond the authorized accessible location. Such a vulnerability compromises the confidentiality of the trusted environment in the application and enables an attacker to launch further attacks by leveraging the exposed information.

Advisory Timeline

  • Published