445
VMScore

CVE-2021-29424

Published: 06/04/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Net::Netmask module prior to 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows malicious users to bypass access control that is based on IP addresses.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

net\\ \\ netmask_project

fedoraproject fedora 32

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #986135 libnet-netmask-perl: CVE-2021-29424: mis-parses IP addresses in some situations Package: libnet-netmask-perl; Maintainer for libnet-netmask-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libnet-netmask-perl is src:libnet-netmask-perl (PTS, buildd, popcon) ...