Description
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
Remediation
References
https://github.com/sass/libsass/issues/2999
Related Vulnerabilities
CVE-2018-3721 Vulnerability in maven package org.webjars.npm:lodash
CVE-2022-24373 Vulnerability in npm package react-native-reanimated
CVE-2022-24614 Vulnerability in maven package com.drewnoakes:metadata-extractor
CVE-2022-36896 Vulnerability in maven package com.compuware.jenkins:compuware-scm-downloader
CVE-2017-16030 Vulnerability in maven package org.webjars.npm:useragent