Junglewise Threat Intelligence

CVE-2016-15059: Net::IDN::Punycode heap buffer overflow in encode_punycode

CVE-2016-15059 · Severity: critical · CVSS 9.8 · Published 2026-09-22

Technologies: CPAN Net::IDN::Punycode. Vendors: CPAN.

Executive brief

Net::IDN::Punycode is a Perl library for encoding domain names using Punycode. The XS backend contains a heap buffer overflow vulnerability where certain inputs cause writes past the allocated output buffer, corrupting heap memory and potentially allowing code execution or denial of service.

Technical details

The XS implementation of encode_punycode allocates an output buffer based on input length but fails to check buffer bounds before writing the final digit of each encoding round and the terminating NUL byte. An attacker-controlled input string whose encoded form fills or exceeds the buffer causes unchecked writes past the allocated region. The pure Perl backend is unaffected; only code using the XS backend is vulnerable.

Affected products

  • CPAN Net::IDN::Punycode before 2.301

Timeline

  • 2016-09-22: disclosed
  • 2016-12-03: patched

References

Related threats