Re: [Dnsmasq-discuss] Open CVEs against dnsmasq

2022-02-20 Thread Hauke Mehrtens
Hi Simon, On 2/15/22 10:56, Simon Kelley wrote: I analysed a couple and came to the same conclusion. Have you looked in detail at all of them? No, I did not look in detail into them, I just had a quick look at them. Thanks for looking deeper. The reports are all machine generated by the

Re: [Dnsmasq-discuss] Open CVEs against dnsmasq

2022-02-19 Thread Simon Kelley
On 14/02/2022 22:32, Hauke Mehrtens wrote: Hi, Our CVE checking scripts in OpenWrt found the following recently opened CVEs against dnsmasq: https://nvd.nist.gov/vuln/detail/CVE-2021-45951 https://nvd.nist.gov/vuln/detail/CVE-2021-45952 https://nvd.nist.gov/vuln/detail/CVE-2021-45953

Re: [Dnsmasq-discuss] Open CVEs against dnsmasq

2022-02-15 Thread Simon Kelley
I analysed a couple and came to the same conclusion. Have you looked in detail at all of them? The reports are all machine generated by the Google fuzzer. The problem is that the fuzzing framework it's using is wrong. The framework was done by a third party over year ago, I was aware of it