CVE-2014-3554: Libndp

Medium severity, CVSS 6.8. EPSS: 2.8% chance of exploitation in the next 30 days.

Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS Search List (DNSSL) in an IPv6 router advertisement.

Affected products

  • Libndp Libndp: before 1.4 (fixed in 1.4)

Published 2014-07-31. Last modified 2026-06-17.