{"id":"CVE-2023-42444","aliases":["GHSA-whhr-7f2w-qqj2","RUSTSEC-2023-0082"],"url":"https://o3.security/vulnerability/CVE-2023-42444","summary":"phonenumber panics on parsing crafted RF3966 inputs","details":"phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment of `rust-phonenumber`, this may get triggered by feeding a maliciously crafted phonenumber over the network, specifically the string `.;phone-context=`. Versions `0.3.3+8.13.9` and `0.2.5+8.11.3` contain a patch for this issue. There are no known workarounds.","published":"2023-09-19T14:47:22.026Z","modified":"2026-08-12T03:51:46.648670038Z","cvss":{"score":8.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"phonenumber","fixedVersion":"0.2.5"},{"ecosystem":"crates.io","name":"phonenumber","fixedVersion":"0.3.3"}],"fix":{"url":"https://github.com/whisperfish/rust-phonenumber/commit/2dd44be94539c051b4dee55d1d9d349bd7bedde6","label":"whisperfish/rust-phonenumber@2dd44be"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/42xxx/CVE-2023-42444.json"},{"type":"ADVISORY","url":"https://github.com/whisperfish/rust-phonenumber/security/advisories/GHSA-whhr-7f2w-qqj2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42444"},{"type":"FIX","url":"https://github.com/whisperfish/rust-phonenumber/commit/2dd44be94539c051b4dee55d1d9d349bd7bedde6"},{"type":"FIX","url":"https://github.com/whisperfish/rust-phonenumber/commit/bea8e732b9cada617ede5cf51663dba183747f71"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.648670038Z"}}