logoalt Hacker News

eruyesterday at 11:09 AM1 replyview on HN

Also in eg C code, many exploits start out would only be a DoS, but can later be turned into a more dangerous attack.


Replies

staticassertionyesterday at 2:32 PM

If you're submitting a CVE for a primitive that seems likely to be useful for further exploitation, mark it as such. That's not the case for ReDOS or the vast majority of DoS, it's already largely the case that you'd mark something as "privesc" or "rce" if you believe it provides that capability without necessarily having a full, reliable exploit.

CVEs are at the discretion of the reporter.