CVE-2022-43358: High severity libsass vulnerability
Stack overflow vulnerability in astselectors.cpp: in function Sass::ComplexSelector::hasplaceholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43358?
CVE-2022-43358 is a stack overflow vulnerability in the ast_selectors.cpp file in the libsass library, specifically in the function Sass::ComplexSelector::has_placeholder. It can be exploited by attackers to cause a denial of service (DoS).
How severe is CVE-2022-43358?
CVE-2022-43358 has a severity rating of 7.5, which is considered high.
What software is affected by CVE-2022-43358?
The affected software is Sass-lang Libsass version 3.6.5-8-g210218.
How can CVE-2022-43358 be exploited?
CVE-2022-43358 can be exploited by attackers to cause a denial of service (DoS) by triggering a stack overflow in the Sass::ComplexSelector::has_placeholder function.
Is there a fix for CVE-2022-43358?
Yes, it is recommended to update to a fixed version of the libsass library to mitigate the vulnerability.