Launchpad.net

CVE 2018-19839

In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service resulting from a heap-based buffer over-read via a crafted sass file.

See the CVE page on Mitre.org for more details.