- Package:
- src:libnet-whois-raw-perl
- Source:
- src:libnet-whois-raw-perl
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-05 22:01:06 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for libnet-whois-raw-perl. CVE-2026-19954[0]: | Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois | command-line tool that queries WHOIS for the wrong domain for | unicode domain names. pwhois encodes each non-ASCII label directly | using Net::IDN::Punycode and prepends xn--. Apart from lowercasing | ASCII and Cyrillic letters, it skips the IDNA mapping and | normalization steps, so a label with other uppercase letters, or not | in NFC, encodes to a different A-label than its IDNA form. For | example, a label of U+00C9 followed by "cole" encodes to "xn--cole- | pka" rather than "xn--cole-9oa". The Net::Whois::Raw library | modules are not affected. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-19954 https://www.cve.org/CVERecord?id=CVE-2026-19954 [1] https://github.com/regru/Net-Whois-Raw/issues/34 [2] https://github.com/regru/Net-Whois-Raw/pull/35 [3] https://security.metacpan.org/patches/N/Net-Whois-Raw/2.99043/CVE-2026-19954-r1.patch Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1150069 in libnet-whois-raw-perl reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/perl-team/modules/packages/libnet-whois-raw-perl/-/commit/f163b12fd5ef2be7ca196e3e3bf377133b5c3061 ------------------------------------------------------------------------ Fix CVE-2026-19954 by correctly encoding unicode domain names Closes: #1150069 ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1150069
We believe that the bug you reported is fixed in the latest version of
libnet-whois-raw-perl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1150069@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated libnet-whois-raw-perl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 05 Oct 2026 17:34:14 +0200
Source: libnet-whois-raw-perl
Architecture: source
Version: 2.99043-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Perl Group <pkg-perl-maintainers@lists.alioth.debian.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1150069
Changes:
libnet-whois-raw-perl (2.99043-2) unstable; urgency=medium
.
* Team upload.
* Fix CVE-2026-19954 by correctly encoding unicode domain names
(Closes: #1150069)
Checksums-Sha1:
1295f43d7cff134e701883c7ec4e5cdd120bf88b 2591 libnet-whois-raw-perl_2.99043-2.dsc
5688849d491da85644aae6c9cc9e61b8a5647bce 4696 libnet-whois-raw-perl_2.99043-2.debian.tar.xz
Checksums-Sha256:
ad5e9e2c56dcba2e6d64a51f5946f511beb52e684c248ba5fe12c1990197da55 2591 libnet-whois-raw-perl_2.99043-2.dsc
79e36eabb9d8bd5fbafa3444beb589bc0ee8e8d4403f43b650d15e6a1e4d733a 4696 libnet-whois-raw-perl_2.99043-2.debian.tar.xz
Files:
fe23ba4275cb4b254e1b11024cdd8a21 2591 perl optional libnet-whois-raw-perl_2.99043-2.dsc
ffdb0039a35b32696ab6d7ff18981c80 4696 perl optional libnet-whois-raw-perl_2.99043-2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmrEEgNfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EVrwP/RuGJ6JRj+07v+v+AfZwFxDlh0tnb6KG
1IHq8nNaT7SbeemUyfg4hhJx2U2lGYdBnXnVkHsWkncH+jZPY8jItemaNSfb3A4q
X/4YWHXeSEvjnOgHOMXVD1EKcLQFpFBb9luPkBb1D8FfXuLhiEUm4hpAxTf6XGj3
FiQNEz4bWVTcPNqA2ptmeabsxZ+CZYX+n/xEn/1isI82b0CtX+vwPkCSQjRdm5p+
wPgl6ChslGhIABNy6LbgLQVRRi6DxxtL515J1Kqp7vp/dFRkjQZgstjCCpc7xcN4
GOzVMFtmiwyMmWayck/VFt+et4VFKIhsFfTZaW9M629nMfLtpsUrU5VvfUd0/Hlz
rcNXyZ8rYOSmjuz6/VrCXbKnsYujsBBUf35vhXQn5Hf4LsR8MguSfzF7lzE8oWXH
vmfMRU8T67DKptZbuwdGvxi/M+tExUZU+BUp3HpHawxq7GwQWo8yX1xc6JaPEVhh
lFDqhU8bBn7iyorL9s2Dcb5c/rig8wAVb+h1LGNbCXiu8BCc73SlGXnu5h1khX1e
oZMYYck/YpAjwoFY28EcoaYhxUVypVhMqMEh35T43qiGFZJg5GdC31TTyT1I9rG8
a+DDVEU6m6yswKHgYqWeAGYDg2XwKzN1l1m3FQYjyTCMSFfMTDlTMN+JLkgFAvF6
rLGAGwVR5evI
=4MK+
-----END PGP SIGNATURE-----