oss-sec mailing list archives
Re: Questionable CVE's reported against dnsmasq
From: Peter Gutmann <pgut001 () cs auckland ac nz>
Date: Mon, 3 Nov 2025 12:53:31 +0000
Russ Allbery <eagle () eyrie org> writes:
This is a bit of an "ask the Lazyweb" question since I have done only minimal research, but is there any way for me to declare, as the software maintainer, what I consider to be the security boundaries of the software in a way that can be at least partially machine-readable?
Even before getting into that, how do you document that people shouldn't do certain things with their config files, or by extension which bits are inside and outside the security boundary? "If an unauthorised party can modify your config files then bad things can happen" seems redundant, "We take no responsibility for what happens if you fail to take unspecified steps to secure your config files" might be correct but will be perceived as blame-the- victim... how do you document this for users? Peter.
Current thread:
- Re: Questionable CVE's reported against dnsmasq, (continued)
 - Re: Questionable CVE's reported against dnsmasq Douglas Bagnall (Oct 29)
 - Re: Questionable CVE's reported against dnsmasq Art Manion (Oct 31)
 - Re: Questionable CVE's reported against dnsmasq Solar Designer (Oct 31)
 - Re: Questionable CVE's reported against dnsmasq Art Manion (Nov 01)
 - Re: Questionable CVE's reported against dnsmasq Russ Allbery (Nov 01)
 - Re: Questionable CVE's reported against dnsmasq Collin Funk (Nov 01)
 - Re: Questionable CVE's reported against dnsmasq Solar Designer (Nov 01)
 - Re: Questionable CVE's reported against dnsmasq Jeremy Stanley (Nov 02)
 
- Re: Questionable CVE's reported against dnsmasq Demi Marie Obenour (Nov 01)
 - Re: Questionable CVE's reported against dnsmasq Russ Allbery (Nov 01)
 
- Re: Questionable CVE's reported against dnsmasq Peter Gutmann (Nov 03)
 - Re: Questionable CVE's reported against dnsmasq Russ Allbery (Nov 03)
 - Re: Questionable CVE's reported against dnsmasq Demi Marie Obenour (Nov 03)
 - Re: Questionable CVE's reported against dnsmasq Olle E. Johansson (Nov 02)
 - Re: Questionable CVE's reported against dnsmasq Art Manion (Nov 03)
 - Re: Questionable CVE's reported against dnsmasq Demi Marie Obenour (Oct 28)
 - Re: Questionable CVE's reported against dnsmasq Demi Marie Obenour (Oct 27)
 - Re: Questionable CVE's reported against dnsmasq nightmare . yeah27 (Oct 27)
 - Re: Questionable CVE's reported against dnsmasq Simon McVittie (Oct 28)
 
