Executive brief
Net::IDN::Punycode is a Perl library for encoding domain names using Punycode. The XS backend contains a heap buffer overflow vulnerability where certain inputs cause writes past the allocated output buffer, corrupting heap memory and potentially allowing code execution or denial of service.
Technical details
The XS implementation of encode_punycode allocates an output buffer based on input length but fails to check buffer bounds before writing the final digit of each encoding round and the terminating NUL byte. An attacker-controlled input string whose encoded form fills or exceeds the buffer causes unchecked writes past the allocated region. The pure Perl backend is unaffected; only code using the XS backend is vulnerable.
Affected products
- CPAN Net::IDN::Punycode before 2.301
Timeline
- 2016-09-22: disclosed
- 2016-12-03: patched