Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-47154

Опубликовано: 18 мар. 2024
Источник: debian
EPSS Низкий

Описание

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libnet-cidr-lite-perlfixed0.22-1package

Примечания

  • https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/#net-cidr-litehttpsmetacpanorgreleasenet-cidr-lite

  • https://github.com/stigtsp/Net-CIDR-Lite/commit/23b6ff0590dc279521863a502e890ef19a5a76fc (0.22)

EPSS

Процентиль: 9%
0.00035
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 1 года назад

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 6.3
redhat
больше 1 года назад

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 6.3
nvd
больше 1 года назад

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

suse-cvrf
около 1 года назад

Security update for perl-Net-CIDR-Lite

CVSS3: 6.3
redos
около 1 года назад

Уязвимость perl-Net-CIDR-Lite

EPSS

Процентиль: 9%
0.00035
Низкий