CVE-2011-2939
Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Unicode string, which triggers a heap-based buffer overflow.
- Dan Kogai Encode Module
- ≤ 2.43, 0.93, 0.94, 0.95, 0.96, 0.97, 0.98, 0.99, 1.00, 1.01, 1.10, 1.11, 1.20, 1.21, 1.25, 1.26, 1.28, 1.30, 1.31, 1.32, 1.33, 1.34, 1.40, 1.41, 1.42, 1.50, 1.51, 1.52, 1.53, 1.54, 1.55, 1.56, 1.57, 1.58, 1.59, 1.60, 1.61, 1.62, 1.63, 1.64
- Fix
- Available
- CVSS 2.0
- 5.1 MEDIUM
- EPSS
- 2.7% (85th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2012-01-13
CVE-2011-2939 at NVD
1 known exploit for CVE-2011-2939
Proof-of-concept code and exploit modules indexed by Sploitus