Логотип exploitDog
bind:CVE-2023-42444
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-42444

Количество 2

Количество 2

nvd логотип

CVE-2023-42444

больше 2 лет назад

phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of `rust-phonenumber`, this may get triggered by feeding a maliciously crafted phonenumber over the network, specifically the string `.;phone-context=`. Versions `0.3.3+8.13.9` and `0.2.5+8.11.3` contain a patch for this issue. There are no known workarounds.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-whhr-7f2w-qqj2

больше 2 лет назад

phonenumber panics on parsing crafted RFC3966 inputs

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-42444

phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of `rust-phonenumber`, this may get triggered by feeding a maliciously crafted phonenumber over the network, specifically the string `.;phone-context=`. Versions `0.3.3+8.13.9` and `0.2.5+8.11.3` contain a patch for this issue. There are no known workarounds.

CVSS3: 8.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-whhr-7f2w-qqj2

phonenumber panics on parsing crafted RFC3966 inputs

CVSS3: 7.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу