OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Dailydave] Algorithmic Bugs

From: Steven M. Christey (coleymitre.org)
Date: Wed Jan 10 2007 - 17:32:21 CST


We have some coverage of these kinds of issues in the Common Weakness
Enumeration entry on Algorithmic Complexity at:

  http://cwe.mitre.org/data/definitions/407.html

This includes 6 specific CVE examples, some of which don't involve
hash collisions, and we do reference the Crosby/Wallach paper.

Wandering through the node relationships will find semi-related
issues, especially under its parent, Asymmetric resource consumption
(amplification), CWE-405. Some DailyDave readers will likely quibble
with some of the classification or wording, but we'd be glad for any
feedback.

- Steve
_______________________________________________
Dailydave mailing list
Dailydavelists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave