NA

CVE-2022-26592

Published: 22/08/2023 Updated: 25/08/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function. (CVE-2022-26592) Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by malicious users to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2. (CVE-2022-43357) Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by malicious users to cause a denial of service (DoS). (CVE-2022-43358)

Vulnerable Product Search on Vulmon Subscribe to Product

sass-lang libsass 3.6.5

Vendor Advisories

Debian Bug report logs - #1051894 libsass: CVE-2022-26592 Package: src:libsass; Maintainer for src:libsass is Debian Sass team <pkg-sass-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 13 Sep 2023 21:15:11 UTC Severity: important Tags: security, upstream Forwarded to ht ...
Stack Overflow vulnerability in libsass 365 via the CompoundSelector::has_real_parent_ref function (CVE-2022-26592) Stack overflow vulnerability in ast_selectorscpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:365-8-g210218, which can be exploited by attackers to causea denial of service (DoS) Also affects the command l ...