Description
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
Remediation
References
https://github.com/sass/libsass/issues/2999
Related Vulnerabilities
CVE-2022-42466 Vulnerability in maven package org.apache.isis.core:isis-applib
CVE-2020-22755 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2018-20835 Vulnerability in npm package tar-fs
CVE-2020-26282 Vulnerability in maven package com.browserup:browserup-proxy-rest
CVE-2023-43961 Vulnerability in maven package cn.dev33:sa-token-core