Description
An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
Remediation
References
https://github.com/sass/libsass/issues/2664
https://github.com/sass/libsass/pull/2631
https://github.com/sass/libsass/releases
Related Vulnerabilities
CVE-2021-40660 Vulnerability in maven package org.javadelight:delight-nashorn-sandbox
CVE-2023-46496 Vulnerability in npm package @evershop/evershop
CVE-2019-17633 Vulnerability in maven package org.eclipse.che:assembly-wsmaster-war
CVE-2018-11011 Vulnerability in maven package cc.ryanc:halo
CVE-2021-23331 Vulnerability in maven package com.squareup:connect