Bug#762232: reportbug: has no good category for web apps exploitability

2014-09-19 Thread Toni Mueller
Hello Sandro, On Fri, Sep 19, 2014 at 09:05:08PM +0100, Sandro Tosi wrote: > > Please consider assigning an appropriate category to this kind of > > problem and offer the user to set the security tag on the affected > > report. > > Can you please clarify what is this "category" you're describing

Bug#762232: reportbug: has no good category for web apps exploitability

2014-09-19 Thread Sandro Tosi
>> From what you describe, I think the right categorization for now is: >> severity=critical, tags=security - what would be the advantage of >> introducing a more fine grained categorization for those issues? > > To me, "critical" seemed to be reserved for root exploits. But the > attacker does not

Bug#762232: reportbug: has no good category for web apps exploitability

2014-09-19 Thread Sandro Tosi
Hello Toni, thanks for your report > as the number of packaged web papplications increases, reportbug should > imho have a category that is designated to be appropriate for cases > where the problem does not allow compromising a local user or gaining > root, but where the application would make th

Bug#762232: reportbug: has no good category for web apps exploitability

2014-09-19 Thread Toni Mueller
Package: reportbug Version: 6.4.4+deb7u1 Severity: wishlist Dear Maintainer, as the number of packaged web papplications increases, reportbug should imho have a category that is designated to be appropriate for cases where the problem does not allow compromising a local user or gaining root, but