CVE-2019-6286 (NVD)

2019-01-14

In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called from Sass::Parser::parse_import(), a similar issue to CVE-2018-11693.

Products Libsass
Type Out-of-bounds Read (CWE-125)
First patch - None (likely due to unavailable code)
Links https://github.com/sass/libsass/issues/2815
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00047.html