stable

perl-Net-CIDR-0.27-1.el10_1

FEDORA-EPEL-2026-c2d409a4ce created by pghmcfc 4 months ago for Fedora EPEL 10.1

This update fixes handling of leading zeroes.

The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. In some cases an attacker may be able to leverage this to bypass access controls based on IP addresses.

This update has been submitted for testing by pghmcfc.

4 months ago

This update's test gating status has been changed to 'ignored'.

4 months ago

This update has been pushed to testing.

4 months ago

This update has been submitted for stable by bodhi.

4 months ago

This update has been pushed to stable.

4 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-1
Stable by Karma
2
Stable by Time
7 days
Dates
submitted
4 months ago
in testing
4 months ago
in stable
4 months ago
approved
4 months ago
BZ#2443232 CVE-2021-4456 Net-CIDR: mishandling of leading zeros in IP CIDR addresses
0
0
BZ#2443386 CVE-2021-4456 perl-Net-CIDR: mishandling of leading zeros in IP CIDR addresses [epel-all]
0
0

Automated Test Results