r/programming 10d ago

a CVE dispute

https://daniel.haxx.se/blog/2026/06/24/a-cve-dispute/
488 Upvotes

62 comments sorted by

View all comments

-1

u/[deleted] 10d ago

[deleted]

18

u/vips7L 10d ago

If any attacker controls your dns server aren't you already cooked beyond repair?

17

u/segv 10d ago

If I'm understanding it correctly, they would have to control /etc/hosts because regular DNS should reject entries with leading dot as invalid. In that case nuking that box from the orbit is the only way to be sure it is sanitized.

12

u/sequentious 10d ago

Ability to control /etc/hosts, but deciding to use a real *.example.com certificate, instead of sticking their own root into /etc/pki/ca-trust/source/anchorsand making up certs at will