Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whhr-7f2w-qqj2

Опубликовано: 21 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

phonenumber panics on parsing crafted RFC3966 inputs

Impact

The phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string.

In a typical deployment of rust-phonenumber, this may get triggered by feeding a maliciously crafted phonenumber over the network, specifically the string .;phone-context=.

Patches

Patches will be published as version 0.3.3+8.13.9 and backported as 0.2.5+8.11.3.

Workarounds

n.a.

References

n.a.

Пакеты

Наименование

phonenumber

rust
Затронутые версииВерсия исправления

< 0.2.5

0.2.5

Наименование

phonenumber

rust
Затронутые версииВерсия исправления

>= 0.3.0, < 0.3.3

0.3.3

EPSS

Процентиль: 67%
0.00552
Низкий

7.5 High

CVSS3

Дефекты

CWE-1284
CWE-248
CWE-392

Связанные уязвимости

CVSS3: 8.6
nvd
больше 2 лет назад

phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of `rust-phonenumber`, this may get triggered by feeding a maliciously crafted phonenumber over the network, specifically the string `.;phone-context=`. Versions `0.3.3+8.13.9` and `0.2.5+8.11.3` contain a patch for this issue. There are no known workarounds.

EPSS

Процентиль: 67%
0.00552
Низкий

7.5 High

CVSS3

Дефекты

CWE-1284
CWE-248
CWE-392