|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2022-43357: sassc,libsass: Stack overflow vulnerability in ast_selectors.cpp in function Sass:CompoundSelector:has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Stoyan Manolov <stoyan.manolov> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | coldpool, mvetter, pgajdos, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/376039/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2022-43357:5.3:(AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H) | ||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Stoyan Manolov
2023-08-24 11:36:20 UTC
No change in upstream bug. No news in upstream bug. No news in upstream bug. I did some research and commented my findings at: https://github.com/sass/libsass/issues/3177#issuecomment-1854445404 And could motivate upstream maintainer Marcel Greter to provide: https://github.com/sass/libsass/pull/3184 which fixes this issue. I backported these changes as libsass-CVE-2022-43357,CVE-2022-43358,CVE-2022-26592.patch and ran them against all 3 POCs, which are now solved. SR#1133374 to devel:libraries:c_c++/libsass SR#315778 to SUSE_SLE-15-SP2_Update SUSE-SU-2023:4895-1: An update that solves three vulnerabilities can now be installed. Category: security (moderate) Bug References: 1214573, 1214575, 1214576 CVE References: CVE-2022-26592, CVE-2022-43357, CVE-2022-43358 Sources used: SUSE Package Hub 15 15-SP4 (src): libsass-3.6.5-150200.4.10.1 SUSE Package Hub 15 15-SP5 (src): libsass-3.6.5-150200.4.10.1 openSUSE Leap 15.4 (src): libsass-3.6.5-150200.4.10.1 openSUSE Leap 15.5 (src): libsass-3.6.5-150200.4.10.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. |