Site icon 지락문화예술공작단

USN-2980-1: libndp vulnerability

USN-2980-1: libndp vulnerability

Ubuntu Security Notice USN-2980-1

17th May, 2016

libndp vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

Summary

libndp could be tricked into accepting an NDP message from outside the
local network.

Software description

Details

Julien Bernard discovered that libndp incorrectly performed origin checks
when receiving Neighbor Discovery Protocol (NDP) messages. A remote
attacker outside of the local network could use this issue to advertise a
node as a router, causing a denial of service, or possibly to act as a man
in the middle.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 16.04 LTS:
libndp0

1.4-2ubuntu0.16.04.1
Ubuntu 15.10:
libndp0

1.4-2ubuntu0.15.10.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

CVE-2016-3698

Source: USN-2980-1: libndp vulnerability

Exit mobile version