Description
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
Remediation
References
https://github.com/sass/libsass/issues/2999
Related Vulnerabilities
CVE-2022-39249 Vulnerability in npm package matrix-js-sdk
CVE-2017-16159 Vulnerability in npm package caolilinode
CVE-2022-24725 Vulnerability in npm package shescape
CVE-2021-23354 Vulnerability in npm package printf
CVE-2023-22467 Vulnerability in maven package org.webjars.bowergithub.moment:luxon