Re: Bug severity for substantial DoS vulnerability

2003-04-16 Thread Jamie Heilman
Florian Weimer wrote: > What's the correct severity for substantial DoS vulnerabilities? I'd gauge it a little based on how popular the software is in the vulnerable configuration (which is something of a crapshoot). Sounds like you're talking about remotely exploitable as well, which I guess ear

Bug severity for substantial DoS vulnerability

2003-04-16 Thread Florian Weimer
What's the correct severity for substantial DoS vulnerabilities? Substantial DoS vulnerabilities enable attackers to make a system completely unusable, with little effort (say, a stream of a few hundred small packets per second). If I read the guidelines correctly, it's either "important" or "gra