Description
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471782
Related Vulnerabilities
CVE-2015-8862 Vulnerability in maven package org.webjars.npm:mustache
CVE-2022-4742 Vulnerability in npm package json-pointer
CVE-2021-21141 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-25927 Vulnerability in maven package org.webjars.bowergithub.faisalman:ua-parser-js
CVE-2023-50137 Vulnerability in maven package com.jfinal:jfinal