Description
An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
Remediation
References
https://github.com/sass/libsass/issues/2664
https://github.com/sass/libsass/pull/2631
https://github.com/sass/libsass/releases
Related Vulnerabilities
CVE-2020-7715 Vulnerability in npm package deep-get-set
CVE-2019-10787 Vulnerability in npm package im-resize
CVE-2007-5333 Vulnerability in maven package tomcat:tomcat-coyote
CVE-2023-33201 Vulnerability in maven package org.bouncycastle:bcprov-jdk18on
CVE-2014-3120 Vulnerability in maven package org.elasticsearch:elasticsearch