CVE-2023-42444

CVSS V2 None CVSS V3 None
Description
phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of `rust-phonenumber`, this may get triggered by feeding a maliciously crafted phonenumber over the network, specifically the string `.;phone-context=`. Versions `0.3.3+8.13.9` and `0.2.5+8.11.3` contain a patch for this issue. There are no known workarounds.
Overview
  • CVE ID
  • CVE-2023-42444
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-09-19T14:47:22.026Z
  • Last Modified Date
  • 2023-09-19T14:47:22.026Z
History
Created Old Value New Value Data Type Notes
2024-06-25 13:34:10 Added to TrackCVE