NA

CVE-2022-43357

Published: 22/08/2023 Updated: 31/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by malicious users to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.

Vulnerable Product Search on Vulmon Subscribe to Product

sass-lang sassc 3.6.2

sass-lang libsass 3.6.5-8-g210218

Vendor Advisories

Debian Bug report logs - #1051893 libsass: CVE-2022-43357 Package: src:libsass; Maintainer for src:libsass is Debian Sass team <pkg-sass-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 13 Sep 2023 21:15:09 UTC Severity: important Tags: security, upstream Forwarded to ht ...
Stack Overflow vulnerability in libsass 365 via the CompoundSelector::has_real_parent_ref function (CVE-2022-26592) Stack overflow vulnerability in ast_selectorscpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:365-8-g210218, which can be exploited by attackers to causea denial of service (DoS) Also affects the command l ...

Github Repositories

How to become a packager

Awesome Package Maintainer or How to Become a Packager Hint: Use GitHubs TOC icon at the upper right corner of this Readme for easier navigation Goals: short general introduction on what are packages and why we have them general collection of tools and processes that packagers use and follow general collection of tips, snippets and best practises useful for packagers of all d