Wind River Support Network

HomeDefectsLIN1022-5160
Acknowledged

LIN1022-5160 : Security Advisory - libsass - CVE-2022-43357

Created: Aug 22, 2023    Updated: Sep 5, 2023
Found In Version: 10.22.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.

CREATE(Triage):(User=admin) CVE-2022-43357 (https://nvd.nist.gov/vuln/detail/CVE-2022-43357)
Live chat
Online