Description
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.
Remediation
References
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00047.html
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00051.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00027.html
https://github.com/sass/libsass/issues/2816
Related Vulnerabilities
CVE-2023-50578 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2021-31405 Vulnerability in maven package com.vaadin:vaadin-text-field-flow
CVE-2017-16151 Vulnerability in maven package org.webjars.npm:electron
CVE-2018-12532 Vulnerability in maven package org.richfaces:richfaces-a4j
CVE-2019-16303 Vulnerability in npm package generator-jhipster-kotlin