Overview
Request 714783 accepted
- Update version to 3.6.1:
* Fix use-after-free vulnerability in sass_context.cpp:handle_error
bsc#1096894, CVE-2018-11499
* Disallow parent selector in selector_fns arguments
bsc#1118301, CVE-2018-19797
* Fix use-after-free vulnerability exists in the SharedPtr class
bsc#1118346, CVE-2018-19827
* Fix stack-overflow in Eval::operator()
bsc#1118348, CVE-2018-19837
* Fix stack-overflow at IMPLEMENT_AST_OPERATORS expansion
bsc#1118349, CVE-2018-19838
* Fix buffer-overflow (OOB read) against some invalid input
bsc#1118351, CVE-2018-19839
* Fix Null pointer dereference in Sass::Eval::operator()(Sass::Supports_Operator*)
bsc#1119789, CVE-2018-20190
* Fix heap-buffer-overflow in Sass::Prelexer::parenthese_scope(char const*)
bsc#1121943, CVE-2019-6283
* Fix heap-based buffer over-read exists in Sass:Prelexer:alternatives
bsc#1121944, CVE-2019-6284
* Fix heap-based buffer over-read exists in Sass:Prelexer:skip_over_scopes
bsc#1121945, CVE-2019-6286
* Fix uncontrolled recursion in Sass:Parser:parse_css_variable_value
bsc#1133200, CVE-2018-20821
* Fix stack-overflow at Sass::Inspect::operator()
bsc#1133201, CVE-2018-20822
- Created by cbosdonnat
- In state accepted
Request History
cbosdonnat created request
- Update version to 3.6.1:
* Fix use-after-free vulnerability in sass_context.cpp:handle_error
bsc#1096894, CVE-2018-11499
* Disallow parent selector in selector_fns arguments
bsc#1118301, CVE-2018-19797
* Fix use-after-free vulnerability exists in the SharedPtr class
bsc#1118346, CVE-2018-19827
* Fix stack-overflow in Eval::operator()
bsc#1118348, CVE-2018-19837
* Fix stack-overflow at IMPLEMENT_AST_OPERATORS expansion
bsc#1118349, CVE-2018-19838
* Fix buffer-overflow (OOB read) against some invalid input
bsc#1118351, CVE-2018-19839
* Fix Null pointer dereference in Sass::Eval::operator()(Sass::Supports_Operator*)
bsc#1119789, CVE-2018-20190
* Fix heap-buffer-overflow in Sass::Prelexer::parenthese_scope(char const*)
bsc#1121943, CVE-2019-6283
* Fix heap-based buffer over-read exists in Sass:Prelexer:alternatives
bsc#1121944, CVE-2019-6284
* Fix heap-based buffer over-read exists in Sass:Prelexer:skip_over_scopes
bsc#1121945, CVE-2019-6286
* Fix uncontrolled recursion in Sass:Parser:parse_css_variable_value
bsc#1133200, CVE-2018-20821
* Fix stack-overflow at Sass::Inspect::operator()
bsc#1133201, CVE-2018-20822
factory-auto accepted review
Check script succeeded
maintbot accepted review
ok
licensedigger accepted review
ok
licensedigger approved review
ok
rfrohl moved maintenance target to openSUSE:Maintenance:10631
rfrohl accepted request
ok, thanks
devel:libraries:c_c++/libsass@d12aae3b7f43a4cce140b6b1f73bd465 -> openSUSE:Leap:15.1:Update/libsass
expected origin is 'openSUSE:Leap:15.0' (changed)