Description
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471782
Related Vulnerabilities
CVE-2018-3746 Vulnerability in npm package pdfinfojs
CVE-2022-4742 Vulnerability in maven package org.webjars.npm:json-pointer
CVE-2022-26585 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2018-13797 Vulnerability in npm package macaddress
CVE-2022-26884 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-server