CPANSA-Net-Netmask-2021-01: Net-Netmask vulnerability
Publisher | giterlizzi | Document category | csaf_security_advisory |
---|---|---|---|
Initial release date | 2021-03-29T00:00:00 | Engine | CSAF Perl Toolkit 0.25 |
Current release date | 2021-03-29T00:00:00 | Build Date | |
Current version | 1 | Status | final |
CVSS v3.1 Base Score | 7.5 | Severity | |
Original language | Language | en | |
Also referred to |
Vulnerability Description
The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
Vulnerabilities
CVE-2021-29424
Vulnerability DescriptionThe Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
Weakness | CWE-704 : Incorrect Type Conversion or Cast |
---|
Product status
Known affected
Product | Score | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Net-Netmask less than 2.0000 |
|
Fixed
- Net-Netmask greater than or equal 2.0000
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Net-Netmask-2021-01 JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2021/cpansa-net-netmask-2021-01.json - https://security.netapp.com/advisory/ntap-20210604-0007/ external
https://security.netapp.com/advisory/ntap-20210604-0007/ - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBJVLXJSWN6DKSF5ADUEERI6M23R3GGP/ external
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBJVLXJSWN6DKSF5ADUEERI6M23R3GGP/ - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JF4CYIZELC3NISB3RMV4OCI4GYBC557B/ external
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JF4CYIZELC3NISB3RMV4OCI4GYBC557B/ - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y7JIPQAY5OZ5D3DA7INQILU7SGHTHMWB/ external
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y7JIPQAY5OZ5D3DA7INQILU7SGHTHMWB/ - https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/ external
https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/ - https://metacpan.org/changes/distribution/Net-Netmask#L11-22 external
https://metacpan.org/changes/distribution/Net-Netmask#L11-22 - CVE-2021-29424 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2021-29424
Revision history
Version | Date of the revision | Summary of the revision |
---|---|---|
1 | Mon Mar 29 00:00:00 2021 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/