The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-perl-net-netmask | Jun 18, 2026 | Mar 29, 2021 | |
| Debian | debian-upgrade-libnet-netmask-perl | Jul 30, 2024 | Apr 6, 2021 | |
| Suse | — | suse-upgrade-perl-net-netmask | Aug 9, 2024 | Apr 6, 2021 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Apr 6, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub