Dailydave mailing list archives

Re: Algorithmic Bugs


From: "Steven M. Christey" <coley () mitre org>
Date: Wed, 10 Jan 2007 18:32:21 -0500 (EST)


We have some coverage of these kinds of issues in the Common Weakness
Enumeration entry on Algorithmic Complexity at:

  http://cwe.mitre.org/data/definitions/407.html

This includes 6 specific CVE examples, some of which don't involve
hash collisions, and we do reference the Crosby/Wallach paper.

Wandering through the node relationships will find semi-related
issues, especially under its parent, Asymmetric resource consumption
(amplification), CWE-405.  Some DailyDave readers will likely quibble
with some of the classification or wording, but we'd be glad for any
feedback.

- Steve
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: