Hacker News new | past | comments | ask | show | jobs | submit login

I agree with the rename. I'd suggest

"SQLite (Severity: Critical): Infinite loop due to ORDER BY LIMIT optimization"

It's very arguable that the bit in the brackets is editorialization. On the one hand I added it so nontechnical manager types would go "wait, what" and forward the issue internally so techs learn sooner. On the other hand, the subject itself is bad enough that _most_ will figure it out anyway, and pragmatically speaking this probably isn't going to kill anything by not being fixed within the next 30.8 seconds, so...

Although this could be classed as a security vulnerability because now SQL injection can get you DoS. But the likelihood of the DoS being on a server is arguably low. Definitely nonzero but arguably low.




I think most readers of Hacker News realise that an infinite loop bug is pretty severe.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: