Heap Buffer Overflow in Net::IDN::Punycode for Perl
CVE-2016-15059

Currently unrated

Key Information:

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2016-15059?

A vulnerability exists in earlier versions of Net::IDN::Punycode for Perl where unchecked writes can lead to a heap buffer overflow. This arises during the encoding process of a string through the XS backend, which fails to adequately check the buffer size for the final digits and the terminating NUL character. Consequently, an attacker can exploit this by providing a specially crafted input, leading to potential memory corruption and application instability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.