MGASA-2021-0375

Source
https://advisories.mageia.org/MGASA-2021-0375.html
Import Source
https://advisories.mageia.org/MGASA-2021-0375.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0375
Related
Published
2021-07-27T20:21:53Z
Modified
2021-07-27T19:55:40Z
Summary
Updated perl-Net-Netmask package fixes a security vulnerability
Details

The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses (CVE-2021-29424).

References
Credits

Affected packages

Mageia:8 / perl-Net-Netmask

Package

Name
perl-Net-Netmask
Purl
pkg:rpm/mageia/perl-Net-Netmask?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.100-1.mga8

Ecosystem specific

{
    "section": "core"
}