CWE-131
Incorrect Calculation of Buffer Size
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Soyutlama
Base
Yapı
Simple
Sömürü İhtimali
High
Problemi anla
Problem nedir?
Kök neden
Problem nasıl ve ne zaman oluşur?
Yaşam döngüsü evresi
Implementation
Risk
Başarılı sömürü neye yol açar?
Etkilenen güvenlik alanları: Integrity, Availability, Confidentiality
Savunma
Nasıl önlenir ve çözülür?
Implementation
Uygulama aşaması savunması
Detay
Implementation
Uygulama aşaması savunması
Implementation
Uygulama aşaması savunması
Detay
Implementation
Uygulama aşaması savunması
Implementation
Input Validation
Detay
Implementation
Input Validation
Architecture and Design
Mimari ve tasarım yaklaşımı
Detay
Architecture and Design
Mimari ve tasarım yaklaşımı
Implementation
Uygulama aşaması savunması
Detay
Implementation
Uygulama aşaması savunması
Implementation
Uygulama aşaması savunması
Detay
Implementation
Uygulama aşaması savunması
Implementation
Uygulama aşaması savunması
Detay
Implementation
Uygulama aşaması savunması
Etkinlik: Moderate
This approach is still susceptible to calculation errors, including issues such as off-by-one errors (CWE-193) and incorrectly calculating buffer lengths (CWE-131). Additionally, this only addresses potential overflow issues. Resource consumption / exhaustion issues are still possible.
Implementation
Uygulama aşaması savunması
Detay
Implementation
Uygulama aşaması savunması
Implementation
Uygulama aşaması savunması
Detay
Implementation
Uygulama aşaması savunması
Architecture and Design
Libraries or Frameworks
Detay
Architecture and Design
Libraries or Frameworks
Operation · Build and Compilation
Environment Hardening
Detay
Operation · Build and Compilation
Environment Hardening
Etkinlik: Defense in Depth
This is not necessarily a complete solution, since these mechanisms only detect certain types of overflows. In addition, the result is still a denial of service, since the typical response is to exit the application.
Operation · Build and Compilation
Environment Hardening
Detay
Operation · Build and Compilation
Environment Hardening
Etkinlik: Defense in Depth
These techniques do not provide a complete solution. For instance, exploits frequently use a bug that discloses memory addresses in order to maximize reliability of code execution [REF-1337]. It has also been shown that a side-channel attack can bypass ASLR [REF-1333].
Operation
Environment Hardening
Detay
Operation
Environment Hardening
Etkinlik: Defense in Depth
This is not a complete solution, since buffer overflows could be used to overwrite nearby variables to modify the software's state in dangerous ways. In addition, it cannot be used in cases in which self-modifying code is required. Finally, an attack could still cause a denial of service, since the typical response is to exit the application.
Implementation
Compilation or Build Hardening
Detay
Implementation
Compilation or Build Hardening
Architecture and Design · Operation
Environment Hardening
Detay
Architecture and Design · Operation
Environment Hardening
Architecture and Design · Operation
Sandbox or Jail
Detay
Architecture and Design · Operation
Sandbox or Jail
Etkinlik: Limited
The effectiveness of this mitigation depends on the prevention capabilities of the specific sandbox or jail being used and might only help to reduce the scope of an attack, such as restricting the attacker to certain system calls or limiting the portion of the file system that can be accessed.
Doğrulama
Nasıl tespit edilir?
Automated Static Analysis
HighDetection techniques for buffer-related errors are more mature than for most other weakness types.
Automated Dynamic Analysis
ModerateWithout visibility into the code, black box methods may not be able to sufficiently distinguish this weakness from others, requiring follow-up manual methods to diagnose the underlying problem.
Automated Dynamic Analysis
ModerateCrafted inputs are necessary to reach the code containing the error, such as generated by fuzzers. Also, these tools may reduce performance, and they only report the error condition - not the original mistake that led to the error.
Manual Analysis
Manual Analysis
HighThese may be more effective than strictly automated techniques. This is especially the case with weaknesses that are related to design and business rules.