Description
In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1466411
Related Vulnerabilities
CVE-2022-44262 Vulnerability in maven package org.ff4j:ff4j-core
CVE-2023-2142 Vulnerability in npm package nunjucks
CVE-2019-5483 Vulnerability in npm package seneca
CVE-2021-20262 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2017-18239 Vulnerability in maven package com.jason-goodwin:authentikat-jwt