CVE-2021-29424

The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
Configurations

Configuration 1 (hide)

cpe:2.3:a:net\:\:netmask_project:net\:\:netmask:*:*:*:*:*:perl:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

History

21 Nov 2024, 06:01

Type Values Removed Values Added
References () https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/ - Exploit, Third Party Advisory () https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/ - Exploit, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBJVLXJSWN6DKSF5ADUEERI6M23R3GGP/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBJVLXJSWN6DKSF5ADUEERI6M23R3GGP/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JF4CYIZELC3NISB3RMV4OCI4GYBC557B/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JF4CYIZELC3NISB3RMV4OCI4GYBC557B/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y7JIPQAY5OZ5D3DA7INQILU7SGHTHMWB/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y7JIPQAY5OZ5D3DA7INQILU7SGHTHMWB/ -
References () https://metacpan.org/changes/distribution/Net-Netmask#L11-22 - Release Notes, Third Party Advisory () https://metacpan.org/changes/distribution/Net-Netmask#L11-22 - Release Notes, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20210604-0007/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20210604-0007/ - Third Party Advisory

07 Nov 2023, 03:32

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Y7JIPQAY5OZ5D3DA7INQILU7SGHTHMWB/', 'name': 'FEDORA-2021-c314017fcc', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JF4CYIZELC3NISB3RMV4OCI4GYBC557B/', 'name': 'FEDORA-2021-be62be8c7c', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBJVLXJSWN6DKSF5ADUEERI6M23R3GGP/', 'name': 'FEDORA-2021-3d96cfe6a3', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBJVLXJSWN6DKSF5ADUEERI6M23R3GGP/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JF4CYIZELC3NISB3RMV4OCI4GYBC557B/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y7JIPQAY5OZ5D3DA7INQILU7SGHTHMWB/ -

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-863 CWE-704

Information

Published : 2021-04-06 16:15

Updated : 2024-11-21 06:01


NVD link : CVE-2021-29424

Mitre link : CVE-2021-29424

CVE.ORG link : CVE-2021-29424


JSON object : View

Products Affected

fedoraproject

  • fedora

net\

  • \
CWE
CWE-704

Incorrect Type Conversion or Cast