Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disallow parent selector in selector_fns arguments (Fixes #2779) #2780

Merged
merged 1 commit into from
Dec 9, 2018

Conversation

glebm
Copy link
Contributor

@glebm glebm commented Dec 2, 2018

Fixes #2779

sass-spec: sass/sass-spec#1320

@glebm glebm changed the title Disallow parent selector in selector_fns arguments Disallow parent selector in selector_fns arguments (Fixes #2779) Dec 3, 2018
@xzyfer
Copy link
Contributor

xzyfer commented Dec 7, 2018

Can you please rebase this on master.

@glebm
Copy link
Contributor Author

glebm commented Dec 9, 2018

Rebased

@glebm
Copy link
Contributor Author

glebm commented Dec 9, 2018

Ah, have to rebase the sass-spec PR as well for CI to pass

@xzyfer xzyfer merged commit e94b5f9 into sass:master Dec 9, 2018
@glebm glebm deleted the extend-parent branch December 9, 2018 23:55
@rasendubi
Copy link

Hey guys! I'm trying to fix the CVE-2018-19797 on NixOS. As far as I know, this PR is the only available patch and it does not apply to 3.5.5 release. (There were no src/fn_utils.cpp.)

Would you like to backport the patch to 3.5.x? Releasing a new patch version would be even more awesome 🙂

@xzyfer
Copy link
Contributor

xzyfer commented Dec 28, 2018 via email

@risicle
Copy link

risicle commented May 17, 2019

There are no plans for a new 3.5 release at this time.

Well, that's nice but meanwhile it's six months since any release of this library, leaving users with >3 unpatched CVEs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

A crash in the Selector_List::populate_extends function in both version 3.5.5 and the latest code
4 participants