The 2007 Pwnie Winner For Lamest Vendor Response

OpenBSD IPv6 mbuf kernel buffer overflow (CVE-2007-1365)

OpenBSD team

The OpenBSD team refused to acknowledge the bug as a security vulnerability and issued a “reliability fix” for it. A week later Core Security had developed proof of concept code that demonstrated remote code execution. Read the full timeline and quotes in the Core advisory.

(CVE-2007-1365)