In LibSass, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a denial of service attack. Product bug: https://bugzilla.redhat.com/show_bug.cgi?id=1466411
Created libsass tracking bugs for this issue: Affects: epel-7 [bug 1473186] Affects: fedora-all [bug 1473187]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.