phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of rust-phonenumber, this may get triggered by feeding a maliciously crafted phonenumber, e.g. over the network, specifically strings of the form `+dwPAA;phone-context=AA`, where the "number" part potentially parses as a number larger than 2^56. This vulnerability is fixed in 0.3.6.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-07-09T14:16:38.493Z
Updated: 2024-08-02T04:26:16.016Z
Reserved: 2024-06-27T18:44:13.037Z
Link: CVE-2024-39697
Vulnrichment
Updated: 2024-08-02T04:26:16.016Z
NVD
Status : Awaiting Analysis
Published: 2024-07-09T15:15:11.290
Modified: 2024-11-21T09:28:14.540
Link: CVE-2024-39697
Redhat
No data.