PT-2023-14194 · Libass+2 · Libsass+2

Ex7L0It

·

Published

2023-08-22

·

Updated

2024-06-15

·

CVE-2022-43357

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libsass versions 3.6.5-8-g210218 sassc version 3.6.2
Description The issue is a stack overflow vulnerability in the ast selectors.cpp file, specifically in the Sass::CompoundSelector::has real parent ref function. This vulnerability can be exploited by attackers to cause a denial of service (DoS). The command line driver for libsass, sassc, is also affected.
Recommendations For libsass version 3.6.5-8-g210218, consider updating to a newer version to resolve the issue. For sassc version 3.6.2, consider updating to a newer version to resolve the issue. As a temporary workaround, consider restricting access to the Sass::CompoundSelector::has real parent ref function until a patch is available.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-43714
AZL-44079
BIT-SASS-2022-43357
CVE-2022-43357
OESA-2024-1018
OESA-2024-1049
OPENSUSE-SU-2024:13516-1
SUSE-SU-2023:4895-1

Affected Products

Debian
Libsass
Sassc