Description
An issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.
Remediation
References
https://github.com/sass/libsass/issues/2664
https://github.com/sass/libsass/releases
https://github.com/sass/libsass/pull/2631
Related Vulnerabilities
CVE-2023-46499 Vulnerability in npm package @evershop/evershop
CVE-2020-7642 Vulnerability in maven package org.webjars.bowergithub.afarkas:lazysizes
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core-api
CVE-2020-21122 Vulnerability in maven package com.bstek.ureport:ureport2-console
CVE-2022-25767 Vulnerability in maven package com.bstek.ureport:ureport2-console