Sploitus

CVE-2011-2939

1 known exploit for CVE-2011-2939

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.

Affected products
Encode, Perl, Red Hat
Dan Kogai Encode Module
≤ 2.43, 0.93, 0.94, 0.95, 0.96, 0.97, 0.98, 0.99, 1.00, 1.01, 1.10, 1.11, 1.20, 1.21, 1.25, 1.26, 1.28, 1.30, 1.31, 1.32, 1.33, 1.34, 1.40, 1.41, 1.42, 1.50, 1.51, 1.52, 1.53, 1.54, 1.55, 1.56, 1.57, 1.58, 1.59, 1.60, 1.61, 1.62, 1.63, 1.64
Fix
Available
CVSS 2.0
5.1 MEDIUM
EPSS
2.7% (85th percentile)
Weakness
CWE-189
NVD status
Modified
Published
2012-01-13
CVE-2011-2939 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2011-2939

Proof-of-concept code and exploit modules indexed by Sploitus