Description
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471782
Related Vulnerabilities
CVE-2012-0391 Vulnerability in maven package com.opensymphony:xwork-core
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_2.13
CVE-2020-27216 Vulnerability in maven package org.mortbay.jetty:jetty
CVE-2011-4969 Vulnerability in maven package org.fujion.webjars:jquery
CVE-2022-36025 Vulnerability in maven package org.hyperledger.besu:evm