MGASA-2021-0375 - Updated perl-Net-Netmask package fixes a security vulnerability Publication date: 27 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0375.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-29424 The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses (CVE-2021-29424). References: - https://bugs.mageia.org/show_bug.cgi?id=29023 - https://lists.fedoraproject.org/archives/list/[email protected]/thread/CBJVLXJSWN6DKSF5ADUEERI6M23R3GGP/ - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29424 SRPMS: - 8/core/perl-Net-Netmask-2.0.100-1.mga8