Description
There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1470714
Related Vulnerabilities
CVE-2022-1466 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2021-31635 Vulnerability in maven package com.jfinal:jfinal
CVE-2021-28162 Vulnerability in npm package @wiptheia/core
CVE-2020-7774 Vulnerability in npm package y18n
CVE-2020-11990 Vulnerability in npm package cordova-plugin-camera