Severity
6.8MEDIUMNVD
EPSS
0.6%
top 29.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 31
Latest updateMay 13

Description

Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS Search List (DNSSL) in an IPv6 router advertisement.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

NVDlibndp/libndp< 1.4
debiandebian/libndp< libndp 1.4-1 (bookworm)
Debianlibndp/libndp< 1.4-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-cqq4-c27v-xm7v: Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (crash) and possibly execute arb2022-05-13
OSV
CVE-2014-3554: Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (crash) and possibly execute arb2014-07-31

📋Vendor Advisories

2
Red Hat
libndp: buffer overflow flaw in DNS Search List (DNSSL) handling2014-07-29
Debian
CVE-2014-3554: libndp - Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote...2014

💬Community

2
Bugzilla
CVE-2014-3554 libndp: buffer overflow flaw in DNS Search List (DNSSL) handling [fedora-all]2014-07-29
Bugzilla
CVE-2014-3554 libndp: buffer overflow flaw in DNS Search List (DNSSL) handling2014-07-11
CVE-2014-3554 — Classic Buffer Overflow in Libndp | cvebase