Description
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
Remediation
References
https://github.com/sass/libsass/issues/2999
Related Vulnerabilities
CVE-2021-32620 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2019-5786 Vulnerability in maven package org.webjars.npm:puppeteer
CVE-2020-8131 Vulnerability in npm package yarn
CVE-2020-7691 Vulnerability in npm package jspdf
CVE-2018-6561 Vulnerability in maven package org.webjars.bowergithub.dojo:dijit