CVE-2021-29662
Summary
| CVE | CVE-2021-29662 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-31 18:15:00 UTC |
| Updated | 2023-08-08 14:21:00 UTC |
| Description | The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Data |
|
validate\ |
\ |
ip_project |
data\ |
| Application |
Netapp |
Snapcenter |
- |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Security Issues in Perl IP Address distros - House Absolute(ly) Pointless |
MISC |
blog.urth.org |
|
| security/SICK-2021-018.md at master · sickcodes/security · GitHub |
MISC |
github.com |
|
| CVE-2021-29662 Perl Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| GitHub - houseabsolute/Data-Validate-IP: IPv4 and IPv6 validation methods |
MISC |
github.com |
|
| CVE-2021-29662 - Perl module Data::Validate::IP - Improper Input Validation of octal literals in Perl Data::Validate::IP v0.29 and below results in indeterminate SSRF & RFI vulnerabilities. - Sick Codes - Security Research, Hardware & Software Hacking, Consulting, Linux, IoT, Cloud, Embedded, Arch, Tweaks & Tips! |
MISC |
sick.codes |
|
| Update security note in docs to include mention of is_ip() and friends · houseabsolute/Data-Validate-IP@3bba13c · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179403 Debian Security Update for libdata-validate-ip-perl (CVE-2021-29662)