Description
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.
Remediation
References
https://github.com/sass/libsass/issues/2816
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00047.html
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00051.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00027.html
Related Vulnerabilities
CVE-2020-7744 Vulnerability in maven package com.mintegral.msdk:alphab
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.12
CVE-2022-25848 Vulnerability in npm package static-dev-server
CVE-2022-21164 Vulnerability in npm package node-lmdb
CVE-2021-38294 Vulnerability in maven package org.apache.storm:storm-server