CVE-2022-43357
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
22/08/2023
Last modified:
31/08/2023
Description
Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sass-lang:libsass:3.6.5-8-g210218:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sass-lang:sassc:3.6.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



