Impact
The pwhois command‑line tool in Net::Whois::Raw versions before 2.99044 constructs A‑labels for Unicode domain labels by encoding each non‑ASCII label but omitting full IDNA mapping and normalization. This results in an A‑label that does not match the canonical IDNA form, meaning the WHOIS query is sent for a different domain than intended. The tool’s behavior may cause users to receive WHOIS records for the wrong domain, leading to confusion, incorrect data disclosure, and potential facilitation of phishing or delegating domain lookup errors. The weakness is a format‑string / IDNA handling flaw (CWE‑176).
Affected Systems
The vulnerability affects any installation of Net::Whois::Raw for Perl using a version prior to 2.99044 that relies on the pwhois command‑line tool. Users who employ this tool to query Unicode domain names are exposed. The library modules themselves are not impacted, only the command‑line interface. Systems with older Net::Whois::Raw should be identified and updated as described below.
Risk and Exploitability
The vulnerability is exploitable by locally running the pwhois tool with crafted Unicode domain names. No remote network or privilege escalation is required; the attacker only needs influence over the input supplied to the command. Because the exploit is straightforward and does not rely on undisclosed conditions, the risk is considered moderate. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Applying the official patch or following the workaround to convert the domain name to its ASCII A‑label form mitigates the risk.
OpenCVE Enrichment