CWE -- memory or buffer overflow --- 例子
来源:互联网 发布:吃饭 叫号软件 编辑:程序博客网 时间:2024/05/17 21:39
原文链接:
https://cwe.mitre.org/data/definitions/119.html
Example 1
This example takes an IP address from a user, verifies that it is well formed and then looks up the hostname and copies it into a buffer.
This function allocates a buffer of 64 bytes to store the hostname, however there is no guarantee that the hostname will not be larger than 64 bytes. If an attacker specifies an address which resolves to a very large hostname, then we may overwrite sensitive data or even relinquish control flow to the attacker.
Note that this example also contains an unchecked return value (CWE-252) that can lead to a NULL pointer dereference (CWE-476).
注: 这个例子也存在 NULL pointer dereference 的问题。
hp 指针有可能为NULL,程序里面需要加入这方面的check。
Example 2
This example applies an encoding procedure to an input string and stores it into a buffer.
The programmer attempts to encode the ampersand character in the user-controlled string, however the length of the string is validated before the encoding procedure is applied. Furthermore, the programmer assumes encoding expansion will only expand a given character by a factor of 4, while the encoding of the ampersand expands by 5. As a result, when the encoding procedure expands the string it is possible to overflow the destination buffer if the attacker provides a string of many ampersands.
Example 3
The following example asks a user for an offset into an array to select an item.
The programmer allows the user to specify which element in the list to select, however an attacker can provide an out-of-bounds offset, resulting in a buffer over-read (CWE-126).
Example 4
In the following code, the method retrieves a value from an array at a specific array index location that is given as an input parameter to the method
However, this method only verifies that the given array index is less than the maximum length of the array but does not check for the minimum value (CWE-839). This will allow a negative value to be accepted as the input array index, which will result in a out of bounds read (CWE-125) and may allow access to sensitive memory. The input array index should be checked to verify that is within the maximum and minimum range required for the array (CWE-129). In this example the if statement should be modified to include a minimum range check, as shown below.
- CWE -- memory or buffer overflow --- 例子
- integer overflow to buffer overflow --- 例子
- CWE-121: 基于栈的溢出(Stack-based Buffer Overflow)
- Out-of-Bounds Memory References and Buffer Overflow
- buffer overflow
- buffer overflow
- Buffer Overflow
- Buffer overflow
- Buffer Overflow
- 【例子】windows 2000 wmi service buffer overflow expolit
- CWE --- NULL Pointer Dereference -- 例子
- CWE -- Incorrect Calculation of Buffer Size
- WinRAR buffer overflow
- 关于buffer overflow
- Stack buffer overflow (wiki)
- Buffer-overflow attacks
- 缓存溢出Buffer Overflow
- buffer overflow vulnerability
- OC学习三
- 在Visual Studio中入门F#
- IntelliJ IDEA 源值1.5已过时,将在未来所有版本中删除
- mysql字符串截取函数SUBSTR
- HDU5905(树dp)
- CWE -- memory or buffer overflow --- 例子
- 常见sql查询
- 解决tomcat启动被某个servlet里执行方法死循环tomcat被hold的问题
- 51nod 1218 最长递增子序列 V2 【最长递增+复杂判断】
- JS获取样式
- win10系统1703版本隐藏u盘EFI分区的方法
- Object-c 普通字符串、二进制、十进制、十六进制之间的相互转换
- 字符集编码问题探索
- make && make install