n/libndp-1.6-arm-1.txz
This update fixes a security issue. It was found that libndp did
not properly validate and check the origin of Neighbor Discovery
Protocol (NDP) messages. An attacker on a non-local network could
use this flaw to advertise a node as a router, allowing them to
perform man-in-the-middle attacks on a connecting client, or
disrupt the network connectivity of that client.
Thanks to Julien Bernard (Viagénie) for reporting this issue.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3698
(* Security fix *)