PT-2023-14195 · Libass+1 · Libsass+1

Ex7L0It

·

Published

2023-08-22

·

Updated

2024-06-15

·

CVE-2022-43358

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libsass version 3.6.5-8-g210218
Description The issue is a stack overflow vulnerability in the ast selectors.cpp file, specifically in the Sass::ComplexSelector::has placeholder function. This can be exploited by attackers to cause a denial of service (DoS).
Recommendations For libsass version 3.6.5-8-g210218, consider updating to a newer version that contains a fix for this issue, as using the vulnerable function Sass::ComplexSelector::has placeholder can lead to a denial of service (DoS). At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-43987
AZL-44817
BIT-SASS-2022-43358
CVE-2022-43358
OESA-2024-1018
OESA-2024-1049
OPENSUSE-SU-2024:13516-1
SUSE-SU-2023:4895-1

Affected Products

Debian
Libsass