CVE-2024-39697 is a high-severity vulnerability affecting the 'phonenumber' library (versions 0.3.4 and 0.3.5), which is used for parsing, formatting, and validating international phone numbers. A maliciously crafted phonenumber string, specifically of the form `+dwPAA;phone-context=AA` where the number part is excessively large, can trigger an out-of-bounds access, leading to a denial-of-service (DoS) condition. This vulnerability has a CVSS score of 8.6 (High) due to its network-based attack vector, low attack complexity, and high impact on availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. The issue is resolved in version 0.3.6 of the library.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Whisperfish | Rust-Phonenumber | >= 0.3.4, < 0.3.6CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.