There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attack.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-11605.json"