Description
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471782
Related Vulnerabilities
CVE-2020-5397 Vulnerability in maven package org.springframework:spring-webmvc
CVE-2023-40350 Vulnerability in maven package org.jenkins-ci.plugins:docker-swarm
CVE-2020-9483 Vulnerability in maven package org.apache.skywalking:server-storage-plugin
CVE-2020-7760 Vulnerability in maven package org.apache.marmotta.webjars:codemirror