Overview

Request 714784 accepted

- Update version to 3.6.1:
* Fix use-after-free vulnerability in sass_context.cpp:handle_error
bsc#1096894, CVE-2018-11499
* Disallow parent selector in selector_fns arguments
bsc#1118301, CVE-2018-19797
* Fix use-after-free vulnerability exists in the SharedPtr class
bsc#1118346, CVE-2018-19827
* Fix stack-overflow in Eval::operator()
bsc#1118348, CVE-2018-19837
* Fix stack-overflow at IMPLEMENT_AST_OPERATORS expansion
bsc#1118349, CVE-2018-19838
* Fix buffer-overflow (OOB read) against some invalid input
bsc#1118351, CVE-2018-19839
* Fix Null pointer dereference in Sass::Eval::operator()(Sass::Supports_Operator*)
bsc#1119789, CVE-2018-20190
* Fix heap-buffer-overflow in Sass::Prelexer::parenthese_scope(char const*)
bsc#1121943, CVE-2019-6283
* Fix heap-based buffer over-read exists in Sass:Prelexer:alternatives
bsc#1121944, CVE-2019-6284
* Fix heap-based buffer over-read exists in Sass:Prelexer:skip_over_scopes
bsc#1121945, CVE-2019-6286
* Fix uncontrolled recursion in Sass:Parser:parse_css_variable_value
bsc#1133200, CVE-2018-20821
* Fix stack-overflow at Sass::Inspect::operator()
bsc#1133201, CVE-2018-20822

Loading...

Origin Manager's avatar

Previous comment no longer relevant.

Request History
Cédric Bosdonnat's avatar

cbosdonnat created request

- Update version to 3.6.1:
* Fix use-after-free vulnerability in sass_context.cpp:handle_error
bsc#1096894, CVE-2018-11499
* Disallow parent selector in selector_fns arguments
bsc#1118301, CVE-2018-19797
* Fix use-after-free vulnerability exists in the SharedPtr class
bsc#1118346, CVE-2018-19827
* Fix stack-overflow in Eval::operator()
bsc#1118348, CVE-2018-19837
* Fix stack-overflow at IMPLEMENT_AST_OPERATORS expansion
bsc#1118349, CVE-2018-19838
* Fix buffer-overflow (OOB read) against some invalid input
bsc#1118351, CVE-2018-19839
* Fix Null pointer dereference in Sass::Eval::operator()(Sass::Supports_Operator*)
bsc#1119789, CVE-2018-20190
* Fix heap-buffer-overflow in Sass::Prelexer::parenthese_scope(char const*)
bsc#1121943, CVE-2019-6283
* Fix heap-based buffer over-read exists in Sass:Prelexer:alternatives
bsc#1121944, CVE-2019-6284
* Fix heap-based buffer over-read exists in Sass:Prelexer:skip_over_scopes
bsc#1121945, CVE-2019-6286
* Fix uncontrolled recursion in Sass:Parser:parse_css_variable_value
bsc#1133200, CVE-2018-20821
* Fix stack-overflow at Sass::Inspect::operator()
bsc#1133201, CVE-2018-20822


Origin Manager's avatar

origin-manager added leap-reviewers as a reviewer

Changing to a lower priority origin.

origin: openSUSE:Factory
origin_old: openSUSE:Leap:15.1:Update


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Origin Manager's avatar

origin-manager accepted review

origin: openSUSE:Factory
origin_old: openSUSE:Leap:15.1:Update


Staging Bot's avatar

staging-bot added as a reviewer

Being evaluated by staging project "openSUSE:Leap:15.2:Staging:adi:3"


Staging Bot's avatar

staging-bot accepted review

Picked openSUSE:Leap:15.2:Staging:adi:3


Max Lin's avatar

mlin7442 accepted review

ok


Staging Bot's avatar

staging-bot accepted review

ready to accept


Staging Bot's avatar

staging-bot approved review

ready to accept


Yuchen Lin's avatar

maxlin_factory accepted request

Accept to openSUSE:Leap:15.2

openSUSE Build Service is sponsored by