On 4/28/26 17:03, MOHAMED AZIZ RAHMOUNI wrote:
Hello,

I am reporting a security vulnerability I discovered in traceroute 2.1.2 during manual code review and dynamic fuzzing.

[...]

I am following a 90-day responsible disclosure policy. I intend to publish details publicly on 2026-07-27 unless a patch is available sooner, at which point I will coordinate the disclosure timeline with you.

Please confirm receipt of this report.

Oops.  The oss-security mailing list is public.  If you want to do coordinated disclosure, you might want to avoid sending the initial report to a public mailing list.  :-)

It is very fortunate that, as Dmitry Butskoy indicated in his reply, your copy appears to have been tampered with and the official sources do not have this problem.


-- Jacob


Reply via email to