Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjw4-jj88-v687

Опубликовано: 09 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 9.2
CVSS3: 8.6

Описание

panic on parsing crafted phonenumber inputs

Impact

The phonenumber parsing code may panic due to a reachable assert! guard on the phonenumber string.

In a typical deployment of rust-phonenumber, this may get triggered by feeding a maliciously crafted phonenumber, e.g. over the network, specifically strings of the form +dwPAA;phone-context=AA, where the "number" part potentially parses as a number larger than 2^56.

Since f69abee1/0.3.4/#52.

0.2.x series is not affected.

Patches

Upgrade to 0.3.6 or higher.

Workarounds

n/a

References

Whereas https://github.com/whisperfish/rust-phonenumber/issues/69 did not provide an example code path, property testing found a few: +dwPAA;phone-context=AA.

Пакеты

Наименование

phonenumber

rust
Затронутые версииВерсия исправления

>= 0.3.4, < 0.3.6

0.3.6

EPSS

Процентиль: 36%
0.00149
Низкий

9.2 Critical

CVSS4

8.6 High

CVSS3

Дефекты

CWE-1284
CWE-248
CWE-392

Связанные уязвимости

CVSS3: 8.6
nvd
больше 1 года назад

phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of rust-phonenumber, this may get triggered by feeding a maliciously crafted phonenumber, e.g. over the network, specifically strings of the form `+dwPAA;phone-context=AA`, where the "number" part potentially parses as a number larger than 2^56. This vulnerability is fixed in 0.3.6.

EPSS

Процентиль: 36%
0.00149
Низкий

9.2 Critical

CVSS4

8.6 High

CVSS3

Дефекты

CWE-1284
CWE-248
CWE-392