libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.4-2ubuntu0.16.04.1", "binary_name": "libndp-dbg" }, { "binary_version": "1.4-2ubuntu0.16.04.1", "binary_name": "libndp-dev" }, { "binary_version": "1.4-2ubuntu0.16.04.1", "binary_name": "libndp-dev-dbgsym" }, { "binary_version": "1.4-2ubuntu0.16.04.1", "binary_name": "libndp-tools" }, { "binary_version": "1.4-2ubuntu0.16.04.1", "binary_name": "libndp-tools-dbgsym" }, { "binary_version": "1.4-2ubuntu0.16.04.1", "binary_name": "libndp0" }, { "binary_version": "1.4-2ubuntu0.16.04.1", "binary_name": "libndp0-dbgsym" } ] }