Описание
The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libsass | fixed | 3.6.3-1 | package | |
| libsass | no-dsa | buster | package | |
| libsass | not-affected | stretch | package |
Примечания
https://github.com/sass/libsass/issues/2658
Introduced by: https://github.com/sass/libsass/commit/efd97dae376de50b3e6ed724337c4f274a21491d (3.5.0)
Fixed by: https://github.com/sass/libsass/commit/f2db04883e5fff4e03777dcc1eb60d4373c45be1
EPSS
Связанные уязвимости
The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).
The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).
The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).
The parsing component in LibSass through 3.5.5 allows attackers to cause a denial-of-service (uncontrolled recursion in Sass::Parser::parse_css_variable_value in parser.cpp).
EPSS