CVE-2016-15059

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized from the input length. The loop that emits the digits of each code point checks for room before every write, but the write of the last digit of each round and the write of the terminating NUL do not, so an input whose encoded form fills the buffer writes past its end. Only the XS backend is affected. Encoding an attacker-supplied string corrupts the heap.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-23: 109-23
Referenced assets1 URL
By indicator
Full discourse1 post
  • SecAlerts@SecAlertsCo

    🐪 CVE-2016-15059: Net::IDN::Punycode before 2.301 for Perl has a critical heap buffer overflow in encode_punycode - unchecked writes past the output buffer. CVSS 9.8. Update to 2.301+ now. #cybersecurity #perl #vulnerabilities #ciso https://secalerts.co/vulnerability/CVE-2016-15059?utm_campaign=x https://t.co/xOJaHvYAeW

    0000060
    888 followersView on X

Explore more