Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2016-15059: Perl libnet-idn-encode may corrupt memory during encoding

CVE-2016-15059 · published 7 days ago
Summary

The libnet-idn-encode Perl module used in Debian and by Canonical can overwrite memory when it processes a specially crafted string. This can cause the program to crash or be taken over by an attacker. Upgrade the module to version 2.301 or newer to fix the issue.

What to do
  • Update debian libnet-idn-encode-perl to version 2.303-1.
Affected software
Ecosystem VendorProductAffected versions
Debian:12 debian libnet-idn-encode-perl < 2.303-1
Fix: upgrade to 2.303-1
Ubuntu:16.04:LTS canonical libnet-idn-encode-perl All versions
Original advisory text
DEBIAN-CVE-2016-15059
Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized from the input length. The loop that emits the digits of each code point checks for room before every write, but the write of the last digit of each round and the write of the terminating NUL do not, so an input whose encoded form fills the buffer writes past its end. Only the XS backend is affected. Encoding an attacker-supplied string corrupts the heap.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published22 Sep 2026
Updated27 Sep 2026
First seen22 Sep 2026
Track software like this
Free during beta