A CVE has been assigned for a security issue fixed in dnsmasq 2.76: http://openwall.com/lists/oss-security/2016/06/04/2 The upstream commit that fixed the issue is linked in the message above.
According to Ubuntu, the issue was introduced in 2.73. Closing this.
Status: NEW => RESOLVEDVersion: 5 => CauldronResolution: (none) => FIXED
Thanks David! And I think my antispam ate the first mail :-/ but surprisingly not the second.
URL: (none) => http://lwn.net/Vulnerabilities/692185/