Description
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Remediation
References
https://github.com/sass/libsass/issues/2445
https://bugzilla.redhat.com/show_bug.cgi?id=1471780
Related Vulnerabilities
CVE-2018-3720 Vulnerability in npm package assign-deep
CVE-2020-7723 Vulnerability in npm package promisehelpers
CVE-2020-28191 Vulnerability in maven package org.togglz:togglz-console
CVE-2020-19697 Vulnerability in npm package editor.md
CVE-2017-7664 Vulnerability in maven package org.apache.openmeetings:openmeetings-server