[Dailydave] Algorithmic Bugs

Steven M. Christey coley at mitre.org
Wed Jan 10 18:32:21 EST 2007


We have some coverage of these kinds of issues in the Common Weakness
Enumeration entry on Algorithmic Complexity at:

  http://cwe.mitre.org/data/definitions/407.html

This includes 6 specific CVE examples, some of which don't involve
hash collisions, and we do reference the Crosby/Wallach paper.

Wandering through the node relationships will find semi-related
issues, especially under its parent, Asymmetric resource consumption
(amplification), CWE-405.  Some DailyDave readers will likely quibble
with some of the classification or wording, but we'd be glad for any
feedback.

- Steve


More information about the Dailydave mailing list