CPANSA-Data-Validate-IP-2021-01: Data-Validate-IP vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2021-03-31T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2021-03-31T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | 7.5 | Severity | |
Original language | Language | en | |
Also referred to |
Vulnerability Description
The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
Vulnerabilities
CVE-2021-29662
Vulnerability DescriptionThe Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
Weakness | CWE-704 : Incorrect Type Conversion or Cast |
---|
Product status
Known affected
Product | Score | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Data-Validate-IP less than or equal 0.29 |
|
Fixed
- Data-Validate-IP greater than 0.29
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Data-Validate-IP-2021-01 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2021/cpansa-data-validate-ip-2021-01.json - https://security.netapp.com/advisory/ntap-20210604-0002/ external
https://security.netapp.com/advisory/ntap-20210604-0002/ - https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/ external
https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/ - https://github.com/houseabsolute/Data-Validate-IP external
https://github.com/houseabsolute/Data-Validate-IP - https://github.com/houseabsolute/Data-Validate-IP/commit/3bba13c819d616514a75e089badd75002fd4f14e external
https://github.com/houseabsolute/Data-Validate-IP/commit/3bba13c819d616514a75e089badd75002fd4f14e - https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-018.md external
https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-018.md - https://sick.codes/sick-2021-018/ external
https://sick.codes/sick-2021-018/ - CVE-2021-29662 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2021-29662
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Wed Mar 31 00:00:00 2021 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/