Description
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471780
https://github.com/sass/libsass/issues/2445
Related Vulnerabilities
CVE-2021-43843 Vulnerability in npm package jsx-slack
CVE-2022-38752 Vulnerability in maven package org.yaml:snakeyaml
CVE-2021-34080 Vulnerability in npm package ssl-utils
CVE-2022-36922 Vulnerability in maven package org.jenkins-ci.plugins:lucene-search
CVE-2020-26939 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk14