Bugzilla – Bug 1156130
VUL-1: CVE-2019-18799: libsass: NULL pointer dereference in Sass:Parser:parseCompoundSelector in parser_selectors.cpp
Last modified: 2024-07-04 13:42:34 UTC
CVE-2019-18799 LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-18799 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18799 https://github.com/sass/libsass/issues/3001
SLE15-SP2 and Leap 15.2 (inherited by the former) are tracked as affected
Upstream: https://github.com/sass/libsass/pull/3027 Fixed in all supported codestreams.