CVE-2019-18798 (NVD)

2019-11-06

LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.

Products Libsass
Type Out-of-bounds Read (CWE-125)
First patch - None (likely due to unavailable code)
Links https://github.com/sass/libsass/issues/2999