Candidate: CVE-2018-11499 PublicDate: 2018-05-26 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11499 https://github.com/sass/libsass/issues/2643 Description: A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 that could be leveraged to cause a denial of service (application crash) or possibly unspecified other impact. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900182 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_libsass: upstream: https://github.com/sass/libsass/commit/930857ce4938f64ce1c31463dbd19b1aa781a5f7 upstream_libsass: needs-triage precise/esm_libsass: DNE trusty_libsass: DNE trusty/esm_libsass: DNE xenial_libsass: ignored (end of standard support, was needed) artful_libsass: ignored (reached end-of-life) bionic_libsass: needed cosmic_libsass: ignored (reached end-of-life) disco_libsass: ignored (reached end-of-life) eoan_libsass: not-affected (3.5.5-4) focal_libsass: not-affected (3.5.5-4) groovy_libsass: not-affected (3.5.5-4) hirsute_libsass: not-affected (3.5.5-4) impish_libsass: not-affected (3.5.5-4) jammy_libsass: not-affected (3.5.5-4) devel_libsass: not-affected (3.5.5-4)