PT-2023-28347 · Unknown · Blurhash-Rs

Rubdos

·

Published

2023-09-19

·

Updated

2023-09-22

·

CVE-2023-42447

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions blurhash-rs version 0.1.1
Description The blurhash parsing code may panic due to multiple panic-guarded out-of-bounds accesses on untrusted input. In a typical deployment, this may get triggered by feeding maliciously crafted blurhashes over the network, including UTF-8 compliant strings containing multi-byte UTF-8 characters.
Recommendations For version 0.1.1, update to version 0.2.0, which includes a patch for this issue, noting that it may require user intervention due to slight API churn. As a temporary workaround, consider restricting the input of blurhashes to trusted sources until the update can be applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-42447
CXVP-82CQ-57H2
GHSA-CXVP-82CQ-57H2
RUSTSEC-2023-0083

Affected Products

Blurhash-Rs