CWE-787 là gì?
Đang phân tích dữ liệu...
Đang phân tích dữ liệu...
| Tác động | Phạm vi | Diễn giải |
|---|---|---|
| Thay đổi bộ nhớ, Thực thi mã hoặc lệnh trái phép | Tính toàn vẹn | Write operations could cause memory corruption. In some cases, an adversary can modify control data such as return addresses in order to execute unexpected code. |
| Từ chối dịch vụ: sập, thoát hoặc khởi động lại | Tính sẵn sàng | Attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash. |
| Trạng thái ngoài dự kiến | Khác | Subsequent write operations can produce undefined or unexpected results. |
| Phương pháp | Cách làm | Hiệu quả |
|---|---|---|
| Phân tích tĩnh tự động | This weakness can often be detected using automated static analysis tools. Many modern tools use data flow analysis or constraint-based techniques to minimize the number of false positives. Automated static analysis generally does not account for environmental considerations when reporting out-of-bounds memory operations. This can make it difficult for users to determine which warnings should be investigated first. For example, an analysis tool might report buffer overflows that originate from command line arguments in a program that is not expected to run with setuid or other special privileges.Detection techniques for buffer-related errors are more mature than for most other weakness types. | Cao |
| Phân tích động tự động | This weakness can be detected using dynamic tools and techniques that interact with the software using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, and fault injection. The software's operation may slow down, but it should not become unstable, crash, or generate incorrect results. | — |
| Phân tích động tự động | Use tools that are integrated during compilation to insert runtime error-checking mechanisms related to memory safety errors, such as AddressSanitizer (ASan) for C/C++ [REF-1518].Crafted inputs are necessary to reach the code containing the error, such as generated by fuzzers. Also, these tools may reduce performance, and they only report the error condition - not the original mistake that led to the error. | Khá |
Dưới đây là các lỗ hổng tiêu biểu liên quan đến CWE-787, dựa theo mức độ ưu tiên
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.
Khám phá CyStack VulnScanvi