PT-2023-14195 · Libass+1 · Libsass+1

Ex7L0It

·

Publicado

2023-08-22

·

Atualizado

2024-06-15

·

CVE-2022-43358

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libsass version 3.6.5-8-g210218
Description The issue is a stack overflow vulnerability in the ast selectors.cpp file, specifically in the Sass::ComplexSelector::has placeholder function. This can be exploited by attackers to cause a denial of service (DoS).
Recommendations For libsass version 3.6.5-8-g210218, consider updating to a newer version that contains a fix for this issue, as using the vulnerable function Sass::ComplexSelector::has placeholder can lead to a denial of service (DoS). At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-43987
AZL-44817
BIT-SASS-2022-43358
CVE-2022-43358
OESA-2024-1018
OESA-2024-1049
OPENSUSE-SU-2024:13516-1
SUSE-SU-2023:4895-1

Produtos afetados

Debian
Libsass