7.5

CVE-2022-43357

Exploit
Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sass-langLibsass Version3.6.5-8-g210218
Sass-langSassc Version3.6.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.25% 0.656
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://drive.google.com/file/d/1aC5q3czen0atI91fuBIoCBFkS30_OSWX/
Third Party Advisory
Exploit
Permissions Required
https://github.com/sass/libsass
Product
https://github.com/sass/libsass/issues/3177
Vendor Advisory
Exploit
Issue Tracking