oss-sec mailing list archives
Re: [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing — traceroute 2.1.2
From: Jacob Bachmeyer <jcb62281 () gmail com>
Date: Tue, 28 Apr 2026 22:18:46 -0500
On 4/28/26 17:03, MOHAMED AZIZ RAHMOUNI wrote:
Hello,I am reporting a security vulnerability I discovered in traceroute 2.1.2 during manual code review and dynamic fuzzing.[...]I am following a 90-day responsible disclosure policy. I intend to publish details publicly on 2026-07-27 unless a patch is available sooner, at which point I will coordinate the disclosure timeline with you.Please confirm receipt of this report.
Oops. The oss-security mailing list is public. If you want to do coordinated disclosure, you might want to avoid sending the initial report to a public mailing list. :-)
It is very fortunate that, as Dmitry Butskoy indicated in his reply, your copy appears to have been tampered with and the official sources do not have this problem.
-- Jacob
Current thread:
- [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing — traceroute 2.1.2 MOHAMED AZIZ RAHMOUNI (Apr 28)
- Re: [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing — traceroute 2.1.2 Dmitry Butskoy (Apr 28)
- Re: [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing — traceroute 2.1.2 Dmitry Butskoy (Apr 28)
- Re: [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing — traceroute 2.1.2 Solar Designer (Apr 28)
- Re: [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing — traceroute 2.1.2 Alan Coopersmith (Apr 28)
- Re: [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing — traceroute 2.1.2 Ellenor Bjornsdottir (Apr 28)
- Re: [SECURITY] Out-of-Bounds Read in MPLS Extension Parsing — traceroute 2.1.2 Jacob Bachmeyer (Apr 28)
