>> OpenBSD Security Update Fixes ndp Information Disclosure Vulnerability
Title : OpenBSD Security Update Fixes ndp Information Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2008-2725 CVE ID : CVE-2008-2476 - CVE-2008-4404
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-10-06
Technical Description
A vulnerability has been identified in OpenBSD, which could be exploited by attackers to gain knowledge of sensitive information. This issue is caused by an error in the Neighbor Discovery Protocol (ndp) that does not properly verify neighbor solicitation requests, which could allow an attacker with IPv6 connectivity to the affected router to intercept traffic.