CVE-2014-3554

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
31/07/2014
Last modified:
12/04/2025

Description

Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS Search List (DNSSL) in an IPv6 router advertisement.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libndp:libndp:*:*:*:*:*:*:*:* 1.4 (excluding)