Description
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
Remediation
References
https://github.com/sass/libsass/issues/2999
Related Vulnerabilities
CVE-2021-44138 Vulnerability in maven package com.caucho:resin
CVE-2020-7792 Vulnerability in maven package org.webjars.npm:mout
CVE-2020-36732 Vulnerability in npm package crypto-js
CVE-2020-7788 Vulnerability in maven package org.webjars.npm:ini
CVE-2018-16489 Vulnerability in maven package org.webjars.npm:just-extend