Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-47154

Опубликовано: 18 мар. 2024
Источник: debian
EPSS Низкий

Описание

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libnet-cidr-lite-perlfixed0.22-1package

Примечания

  • https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/#net-cidr-litehttpsmetacpanorgreleasenet-cidr-lite

  • https://github.com/stigtsp/Net-CIDR-Lite/commit/23b6ff0590dc279521863a502e890ef19a5a76fc (0.22)

EPSS

Процентиль: 12%
0.0004
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
почти 2 года назад

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 6.3
redhat
почти 2 года назад

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 6.3
nvd
почти 2 года назад

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

suse-cvrf
почти 2 года назад

Security update for perl-Net-CIDR-Lite

CVSS3: 6.3
github
почти 2 года назад

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

EPSS

Процентиль: 12%
0.0004
Низкий