The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3770-1 | libnet-cidr-lite-perl security update |
Ubuntu USN |
USN-6712-1 | Net::CIDR::Lite vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-15T21:46:52.681Z
Reserved: 2024-03-18T00:00:00
Link: CVE-2021-47154
Updated: 2024-08-04T05:24:39.883Z
Status : Awaiting Analysis
Published: 2024-03-18T05:15:06.140
Modified: 2024-11-21T06:35:30.437
Link: CVE-2021-47154
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Ubuntu USN