COMMON WEAKNESS ENUMERATIONDraft

CWE-681

Incorrect Conversion between Numeric Types

When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

Soyutlama

Base

Yapı

Simple

Sömürü İhtimali

High

Problemi anla

Problem nedir?

When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

Kök neden

Problem nasıl ve ne zaman oluşur?

Yaşam döngüsü evresi

Implementation

Risk

Başarılı sömürü neye yol açar?

Unexpected StateQuality Degradation

Etkilenen güvenlik alanları: Other, Integrity

The program could wind up using the wrong number and generate incorrect results. If the number is used to allocate resources or make a security decision, then this could introduce a vulnerability.

Savunma

Nasıl önlenir ve çözülür?

Implementation

Uygulama aşaması savunması

Detay
Avoid making conversion between numeric types. Always check for the allowed ranges.

Doğrulama

Nasıl tespit edilir?

Automated Static Analysis

High
Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)