Description
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471780
https://github.com/sass/libsass/issues/2445
Related Vulnerabilities
CVE-2018-3785 Vulnerability in npm package git-dummy-commit
CVE-2020-6858 Vulnerability in maven package com.hotels.styx:styx-api
CVE-2020-7635 Vulnerability in npm package compass-compile
CVE-2020-28481 Vulnerability in npm package socket.io
CVE-2023-3276 Vulnerability in maven package cn.hutool:hutool-core