Description
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471780
https://github.com/sass/libsass/issues/2445
Related Vulnerabilities
CVE-2023-34238 Vulnerability in npm package gatsby-transformer-remark
CVE-2023-26155 Vulnerability in npm package node-qpdf
CVE-2023-26158 Vulnerability in maven package org.webjars.npm:mockjs
CVE-2020-7789 Vulnerability in npm package node-notifier
CVE-2022-34114 Vulnerability in maven package io.dataease:dataease-plugin-common