Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Also in eg C code, many exploits start out would only be a DoS, but can later be turned into a more dangerous attack.
 help



If you're submitting a CVE for a primitive that seems likely to be useful for further exploitation, mark it as such. That's not the case for ReDOS or the vast majority of DoS, it's already largely the case that you'd mark something as "privesc" or "rce" if you believe it provides that capability without necessarily having a full, reliable exploit.

CVEs are at the discretion of the reporter.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: