Description
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1471786
Related Vulnerabilities
CVE-2021-23392 Vulnerability in npm package locutus
CVE-2018-16485 Vulnerability in npm package m-server
CVE-2020-14968 Vulnerability in maven package org.webjars.bower:jsrsasign
CVE-2020-2303 Vulnerability in maven package org.jenkins-ci.plugins:active-directory
CVE-2022-40149 Vulnerability in maven package org.codehaus.jettison:jettison