Description
There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1470714
Related Vulnerabilities
CVE-2021-23342 Vulnerability in npm package docsify
CVE-2023-37908 Vulnerability in maven package org.xwiki.rendering:xwiki-rendering-xml
CVE-2022-0436 Vulnerability in maven package org.webjars.npm:grunt
CVE-2015-0250 Vulnerability in maven package org.eclipse.birt.runtime:org.apache.batik.dom
CVE-2018-1306 Vulnerability in maven package org.apache.portals.pluto:portletv3annotateddemo