Upstream information

CVE-2018-11696 at MITRE

Description

An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Inspect::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.

SUSE information

Overall state of this security issue: Revisit

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 6.8
Vector AV:N/AC:M/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
CVSS v3 Scores
  National Vulnerability Database SUSE
Base Score 8.8 4.7
Vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Access Vector Network Local
Access Complexity Low High
Privileges Required None None
User Interaction Required Required
Scope Unchanged Unchanged
Confidentiality Impact High None
Integrity Impact High None
Availability Impact High High
SUSE Bugzilla entry: 1096659 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.