Description
There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1470714
Related Vulnerabilities
CVE-2022-28220 Vulnerability in maven package org.apache.james.protocols:protocols-netty
CVE-2020-28502 Vulnerability in npm package xmlhttprequest
CVE-2023-3414 Vulnerability in maven package io.jenkins.plugins:servicenow-devops
CVE-2021-33587 Vulnerability in npm package css-what
CVE-2021-27582 Vulnerability in maven package org.mitre:openid-connect-server