Bugzilla – Bug 1050148
VUL-1: python3-libsass: Stack-overflow in the sassc of libsass library.
Last modified: 2017-11-07 07:36:02 UTC
Created attachment 733519 [details] Reproducer rh#1471780 There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service. No maintainer for openSUSE References: https://bugzilla.redhat.com/show_bug.cgi?id=1471780 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-11554 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11554 https://github.com/sass/libsass/issues/2445
Fixed in SR https://build.opensuse.org/request/show/537069
release for Leap, done
openSUSE-SU-2017:2939-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 1050148,1050149,1050150,1050151,1050380 CVE References: CVE-2017-11554,CVE-2017-11555,CVE-2017-11556,CVE-2017-11605,CVE-2017-11608 Sources used: openSUSE Leap 42.3 (src): libsass-3.3.2-5.1 openSUSE Leap 42.2 (src): libsass-3.3.2-2.3.1