cbcvebase.
CVE-2016-3698
published 2016-06-13

CVE-2016-3698: libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote…

high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.

Affected

16 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlibndp< libndp 1.6-1 (bookworm)libndp 1.6-1 (bookworm)
libndplibndp<= 1.5
libndplibndp>= 0 < 1.6-11.6-1
libndplibndp>= 0 < 1.6-11.6-1
libndplibndp>= 0 < 1.6-11.6-1
libndplibndp>= 0 < 1.6-11.6-1
redhatenterprise_linux_desktop
redhatenterprise_linux_hpc_node
redhatenterprise_linux_hpc_node_eus
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH