Description
There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1474276
Related Vulnerabilities
CVE-2021-23639 Vulnerability in npm package md-to-pdf
CVE-2021-44521 Vulnerability in maven package org.apache.cassandra:cassandra-all
CVE-2017-0931 Vulnerability in npm package html-janitor
CVE-2022-2564 Vulnerability in maven package org.webjars.npm:mongoose
CVE-2020-1938 Vulnerability in maven package org.apache.tomcat:tomcat-util