logoalt Hacker News

viraptor • today at 2:06 AM • 4 replies • view on HN

> It's therefore a denial of service

That doesn't follow. In the extremely simple example, an adding service returning 1+1=3 has a bug, but it's not a possible DoS situation at all.

> missing but planned features also deny the use of said features

That's not what DoS is.

This whole situation with CVE assigning comes from the whole process being far from ideal. But it doesn't mean it's completely useless and doesn't follow any rules at all.


Replies

Gigachad • today at 2:24 AM

>but it's not a possible DoS situation at all.

Until someone finds there is a user input they can trigger this bug causing some other bit of code to read data from the wrong offset and now it's a whole exploit.

➕ show 1 reply
asdfaoeu • today at 3:09 AM

It's not hard to imagine an application for which 1+1 = 3 leads to security issue.

➕ show 1 reply
nikanj • today at 5:30 AM

That’s not what Mitre thinks though, they are very happy to host a 9.8 severity CVE for 1+1=3. They’ll probably publish one for 1-1=0 too, if you preface with ”The users of mathematics might not be prepared for zero values”

➕ show 2 replies