PT-2023-28347 · Unknown · Blurhash-Rs
Rubdos
·
Published
2023-09-19
·
Updated
2023-09-22
·
CVE-2023-42447
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
blurhash-rs version 0.1.1
Description
The blurhash parsing code may panic due to multiple panic-guarded out-of-bounds accesses on untrusted input. In a typical deployment, this may get triggered by feeding maliciously crafted blurhashes over the network, including UTF-8 compliant strings containing multi-byte UTF-8 characters.
Recommendations
For version 0.1.1, update to version 0.2.0, which includes a patch for this issue, noting that it may require user intervention due to slight API churn. As a temporary workaround, consider restricting the input of blurhashes to trusted sources until the update can be applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blurhash-Rs