PT-2023-14194 · Libass+2 · Libsass+2

Ex7L0It

·

Publicado

2023-08-22

·

Atualizado

2024-06-15

·

CVE-2022-43357

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libsass versions 3.6.5-8-g210218 sassc version 3.6.2
Description The issue is a stack overflow vulnerability in the ast selectors.cpp file, specifically in the Sass::CompoundSelector::has real parent ref function. This vulnerability can be exploited by attackers to cause a denial of service (DoS). The command line driver for libsass, sassc, is also affected.
Recommendations For libsass version 3.6.5-8-g210218, consider updating to a newer version to resolve the issue. For sassc version 3.6.2, consider updating to a newer version to resolve the issue. As a temporary workaround, consider restricting access to the Sass::CompoundSelector::has real parent ref function until a patch is available.

Exploit

Correção

DoS

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-43714
AZL-44079
BIT-SASS-2022-43357
CVE-2022-43357
OESA-2024-1018
OESA-2024-1049
OPENSUSE-SU-2024:13516-1
SUSE-SU-2023:4895-1

Produtos afetados

Debian
Libsass
Sassc