Description
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471780
https://github.com/sass/libsass/issues/2445
Related Vulnerabilities
CVE-2020-26282 Vulnerability in maven package com.browserup:browserup-proxy-rest
CVE-2021-32623 Vulnerability in maven package org.opencastproject:opencast-kernel
CVE-2019-13127 Vulnerability in maven package org.webjars.bowergithub.jgraph:mxgraph
CVE-2020-26870 Vulnerability in maven package org.webjars.bowergithub.cure53:dompurify
CVE-2022-29161 Vulnerability in maven package org.xwiki.platform:xwiki-platform-crypto