Back

CRITICAL

phonenumber panics on parsing crafted phonenumber inputs

Published Jul 9, 2024

Description

phonenumber is a library for parsing, formatting and validating international phone numbers. Since 0.3.4, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of rust-phonenumber, this may get triggered by feeding a maliciously crafted phonenumber, e.g. over the network, specifically strings of the form `+dwPAA;phone-context=AA`, where the "number" part potentially parses as a number larger than 2^56. This vulnerability is fixed in 0.3.6.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 9, 2024
Updated Aug 2, 2024
Reserved Jun 27, 2024
CISA Vulnrichment
Updated Jul 15, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Jul 9, 2024
Updated Aug 2, 2024
Exploited since n/a
EUVD-2024-2383 GHSA-MJW4-JJ88-V687