CVE-2016-3698
published 2016-06-13CVE-2016-3698: libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote…
PriorityP340high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
3.81%
88.9th percentile
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libndp | < libndp 1.6-1 (bookworm) | libndp 1.6-1 (bookworm) |
| libndp | libndp | <= 1.5 | — |
| libndp | libndp | >= 0 < 1.6-1 | 1.6-1 |
| libndp | libndp | >= 0 < 1.6-1 | 1.6-1 |
| libndp | libndp | >= 0 < 1.6-1 | 1.6-1 |
| libndp | libndp | >= 0 < 1.6-1 | 1.6-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libndp: denial of service due to insufficient validation of source of NDP messages
vendor_redhat·2016-05-17·CVSS 8.1
CVE-2016-3698 [HIGH] CWE-20 libndp: denial of service due to insufficient validation of source of NDP messages
libndp: denial of service due to insufficient validation of source of NDP messages
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.
It was found that libndp did not properly validate and check the origin of Neighbor Discovery Protocol (NDP) messages. An attacker on a non-local network could use this flaw to advertise a node as a router, allowing them to perform man-in-the-middle attacks on a connecting client, or disrupt the network connectivity of that client.
Ubuntu
libndp vulnerability
vendor_ubuntu·2016-05-17
CVE-2016-3698 libndp vulnerability
Title: libndp vulnerability
Summary: libndp could be tricked into accepting an NDP message from outside the
local network.
Julien Bernard discovered that libndp incorrectly performed origin checks
when receiving Neighbor Discovery Protocol (NDP) messages. A remote
attacker outside of the local network could use this issue to advertise a
node as a router, causing a denial of service, or possibly to act as a
machine-in-the-middle.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2016-3698: libndp - libndp before 1.6, as used in NetworkManager, does not properly validate the ori...
vendor_debian·2016·CVSS 8.1
CVE-2016-3698 [HIGH] CVE-2016-3698: libndp - libndp before 1.6, as used in NetworkManager, does not properly validate the ori...
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.
Scope: local
bookworm: resolved (fixed in 1.6-1)
bullseye: resolved (fixed in 1.6-1)
forky: resolved (fixed in 1.6-1)
sid: resolved (fixed in 1.6-1)
trixie: resolved (fixed in 1.6-1)
GHSA
GHSA-rj7j-9h37-7pw7: libndp before 1
ghsa_unreviewed·2022-05-17
CVE-2016-3698 [HIGH] CWE-284 GHSA-rj7j-9h37-7pw7: libndp before 1
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.
OSV
CVE-2016-3698: libndp before 1
osv·2016-06-13·CVSS 8.1
CVE-2016-3698 [HIGH] CVE-2016-3698: libndp before 1
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3698 libndp: denial of service due to insufficient validation of source of NDP messages [fedora-all]
bugzilla·2016-05-17·CVSS 8.1
CVE-2016-3698 [HIGH] CVE-2016-3698 libndp: denial of service due to insufficient validation of source of NDP messages [fedora-all]
CVE-2016-3698 libndp: denial of service due to insufficient validation of source of NDP messages [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2016-3698 libndp: denial of service due to insufficient validation of source of NDP messages
bugzilla·2016-04-21·CVSS 8.1
CVE-2016-3698 [HIGH] CVE-2016-3698 libndp: denial of service due to insufficient validation of source of NDP messages
CVE-2016-3698 libndp: denial of service due to insufficient validation of source of NDP messages
A report from e-mail:
> -------- Forwarded Message --------
> From: Julien BERNARD
> To: Dan Williams , Tambet Ingo
> Cc: [email protected], Viagénie Engineering
> Subject: Security issue with IPv6 on NetworkManager
> Date: Wed, 20 Apr 2016 12:56:36 -0400
>
> Hi,
>
> We didn't want to report this in the bug tracker regarding the security
> implications.
>
> We believe that NetworkManager accepts and process Router
> Advertisements
> with Hop Limit lesser than 255 allowing any node that is not on the
> local link to advertise as a router.
> This can be used to perform DoS attacks or to intercept/modify traffic
> of hosts outside of the local link.
>
> This was tested on lab and we managed to
http://www.debian.org/security/2016/dsa-3581http://www.openwall.com/lists/oss-security/2016/05/17/9http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.ubuntu.com/usn/USN-2980-1https://github.com/jpirko/libndp/commit/2af9a55b38b55abbf05fd116ec097d4029115839https://github.com/jpirko/libndp/commit/a4892df306e0532487f1634ba6d4c6d4bb381c7fhttps://rhn.redhat.com/errata/RHSA-2016-1086.htmlhttp://www.debian.org/security/2016/dsa-3581http://www.openwall.com/lists/oss-security/2016/05/17/9http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.ubuntu.com/usn/USN-2980-1https://github.com/jpirko/libndp/commit/2af9a55b38b55abbf05fd116ec097d4029115839https://github.com/jpirko/libndp/commit/a4892df306e0532487f1634ba6d4c6d4bb381c7fhttps://rhn.redhat.com/errata/RHSA-2016-1086.html
2016-06-13
Published