oss-sec mailing list archives

Re: Questionable CVE's reported against dnsmasq


From: Jacob Bachmeyer <jcb62281 () gmail com>
Date: Thu, 13 Nov 2025 19:34:04 -0600

On 11/12/25 20:19, Peter Gutmann wrote:
[...]

[0] For example modify the code/operating environment to introduce a security
     vulnerability, I'll let you decide whether this qualifies as impractical,
     unrealistic, stupid, or several of the above.

Ah yes, the universal arbitrary code execution exploit:  simply replace the program text with malicious code.  :-)

Can we call it CVE-Zero?  :-P


-- Jacob


Current thread: