CVE-2022-43357: High severity libsass vulnerability
Stack overflow vulnerability in astselectors.cpp in function Sass::CompoundSelector::hasrealparentref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-43357.
What is the severity of CVE-2022-43357?
The severity of CVE-2022-43357 is high, with a severity value of 7.5.
What is affected by CVE-2022-43357?
CVE-2022-43357 affects the following software: Sass-lang Libsass version 3.6.5-8-g210218 and Sass-lang Sassc version 3.6.2.
What is the description of CVE-2022-43357?
CVE-2022-43357 is a stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).
How can I fix CVE-2022-43357?
To fix CVE-2022-43357, it is recommended to update to a patched version of Sass-lang Libsass or Sass-lang Sassc as soon as it becomes available.