CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
Soyutlama
Class
Yapı
Simple
Sömürü İhtimali
High
Problemi anla
Problem nedir?
Terminoloji
Alternatif adlar ve kullanım biçimleri
Buffer Overflow
buffer overrun
memory safety
Kök neden
Problem nasıl ve ne zaman oluşur?
Yaşam döngüsü evresi
Implementation
Risk
Başarılı sömürü neye yol açar?
Etkilenen güvenlik alanları: Integrity, Confidentiality, Availability
Etkilenen güvenlik alanları: Availability, Confidentiality
Etkilenen güvenlik alanları: Confidentiality
Savunma
Nasıl önlenir ve çözülür?
Requirements
Language Selection
Detay
Requirements
Language Selection
Architecture and Design
Libraries or Frameworks
Detay
Architecture and Design
Libraries or Frameworks
This is not a complete solution, since many buffer overflows are not related to strings.
Operation · Build and Compilation
Environment Hardening
Detay
Operation · Build and Compilation
Environment Hardening
Etkinlik: Defense in Depth
This is not necessarily a complete solution, since these mechanisms only detect certain types of overflows. In addition, the result is still a denial of service, since the typical response is to exit the application.
Implementation
Uygulama aşaması savunması
Detay
Implementation
Uygulama aşaması savunması
Operation · Build and Compilation
Environment Hardening
Detay
Operation · Build and Compilation
Environment Hardening
Etkinlik: Defense in Depth
These techniques do not provide a complete solution. For instance, exploits frequently use a bug that discloses memory addresses in order to maximize reliability of code execution [REF-1337]. It has also been shown that a side-channel attack can bypass ASLR [REF-1333].
Operation
Environment Hardening
Detay
Operation
Environment Hardening
Etkinlik: Defense in Depth
This is not a complete solution, since buffer overflows could be used to overwrite nearby variables to modify the software's state in dangerous ways. In addition, it cannot be used in cases in which self-modifying code is required. Finally, an attack could still cause a denial of service, since the typical response is to exit the application.
Implementation
Uygulama aşaması savunması
Detay
Implementation
Uygulama aşaması savunması
Etkinlik: Moderate
This approach is still susceptible to calculation errors, including issues such as off-by-one errors (CWE-193) and incorrectly calculating buffer lengths (CWE-131).
Doğrulama
Nasıl tespit edilir?
Automated Static Analysis
HighDetection techniques for buffer-related errors are more mature than for most other weakness types.
Automated Dynamic Analysis
Automated Dynamic Analysis
ModerateCrafted inputs are necessary to reach the code containing the error, such as generated by fuzzers. Also, these tools may reduce performance, and they only report the error condition - not the original mistake that led to the error.
Automated Static Analysis - Binary or Bytecode
SOAR PartialManual Static Analysis - Binary or Bytecode
SOAR PartialDynamic Analysis with Automated Results Interpretation
SOAR PartialDynamic Analysis with Manual Results Interpretation
SOAR PartialManual Static Analysis - Source Code
SOAR PartialAutomated Static Analysis - Source Code
HighArchitecture or Design Review
HighMITRE görseli
Zafiyet ilişkisi ve akışı
