Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2016-15059: Perl libnet-idn-encode may corrupt memory during encoding
CVE-2016-15059 · published 7 days ago
Summary
The libnet-idn-encode Perl module used in Debian and by Canonical can overwrite memory when it processes a specially crafted string. This can cause the program to crash or be taken over by an attacker. Upgrade the module to version 2.301 or newer to fix the issue.
What to do
- Update debian libnet-idn-encode-perl to version 2.303-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | libnet-idn-encode-perl |
< 2.303-1 Fix: upgrade to 2.303-1
|
| Ubuntu:16.04:LTS | canonical | libnet-idn-encode-perl | All versions |
Original advisory text
DEBIAN-CVE-2016-15059
Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized from the input length. The loop that emits the digits of each code point checks for room before every write, but the write of the last digit of each round and the write of the terminating NUL do not, so an input whose encoded form fills the buffer writes past its end. Only the XS backend is affected. Encoding an attacker-supplied string corrupts the heap.
References
- https://github.com/robrwo/Net-IDN-Encode/commit/9a3ba07f15d22c0347eefee9625b012c... Third Party Advisory
- https://metacpan.org/release/CFAERBER/Net-IDN-Encode-2.301/changes Third Party Advisory
- https://rt.cpan.org/Ticket/Display.html?id=118924 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2016-15059 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/09/22/10
- https://ubuntu.com/security/CVE-2016-15059 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2016-15059 Third Party Advisory
- https://lists.security.metacpan.org/cve-announce/msg/43753031/ Third Party Advisory
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published22 Sep 2026
Updated27 Sep 2026
First seen22 Sep 2026
Sources
CVE-2016-15059 · NVD
CVE-2016-15059 · MITRE
DEBIAN-CVE-2016-15059 · OSV
UBUNTU-CVE-2016-15059 · OSV
Track software like this
Free during beta