The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
CVSS Details
- CVSS 3.1 Base Score: 6.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-libnet-cidr-lite-perl | Mar 25, 2024 | Mar 18, 2024 | |
| Suse | — | suse-upgrade-perl-net-cidr-lite | Aug 9, 2024 | Mar 18, 2024 |
| Ubuntu | ubuntu-pro-upgrade-libnet-cidr-lite-perlubuntu-upgrade-libnet-cidr-lite-perl | Mar 26, 2024 | Mar 18, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub