Sounds like a design issue in particular language implementations rather than a problem with the programming technique.
Sounds like a design issue in particular language implementations rather than a problem with the programming technique.
You say this like these are fundamentally separable things? I find this comment deeply confusing. Every single real software stack ever has a layer where the sausage gets made so to speak.
What is the outdated programming practice at fault here?
For this particular CVE? I'm not clear. Possibly none. The writeup didn't provide sufficient detail and I haven't bothered to wade through the code. There may well be a reason recursion won't work here but it certainly isn't general.
I'd be curious to know in this case why resource limits couldn't be enforced for the recursive implementation but could be for the iterative one.