openSUSE 15 Security Update : libsass (SUSE-SU-2023:4895-1)

high Nessus Plugin ID 187071

Language:

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2023:4895-1 advisory.

- Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function.
(CVE-2022-26592)

- Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2. (CVE-2022-43357)

- Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).
(CVE-2022-43358)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected libsass-3_6_5-1 and / or libsass-devel packages.

See Also

https://bugzilla.suse.com/1214573

https://bugzilla.suse.com/1214575

https://bugzilla.suse.com/1214576

http://www.nessus.org/u?08823216

https://www.suse.com/security/cve/CVE-2022-26592

https://www.suse.com/security/cve/CVE-2022-43357

https://www.suse.com/security/cve/CVE-2022-43358

Plugin Details

Severity: High

ID: 187071

File Name: suse_SU-2023-4895-1.nasl

Version: 1.0

Type: local

Agent: unix

Published: 12/19/2023

Updated: 12/19/2023

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-26592

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/18/2023

Vulnerability Publication Date: 8/22/2023

Reference Information

CVE: CVE-2022-26592, CVE-2022-43357, CVE-2022-43358

SuSE: SUSE-SU-2023:4895-1