On 4/28/26 17:03, MOHAMED AZIZ RAHMOUNI wrote:
Hello,
I am reporting a security vulnerability I discovered in traceroute
2.1.2 during manual code review and dynamic fuzzing.
[...]
I am following a 90-day responsible disclosure policy. I intend to
publish details publicly on 2026-07-27 unless a patch is available
sooner, at which point I will coordinate the disclosure timeline with you.
Please confirm receipt of this report.
Oops. The oss-security mailing list is public. If you want to do
coordinated disclosure, you might want to avoid sending the initial
report to a public mailing list. :-)
It is very fortunate that, as Dmitry Butskoy indicated in his reply,
your copy appears to have been tampered with and the official sources do
not have this problem.
-- Jacob