Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: added parasoft

...

Tool

Version

Checker

Description

 Compass/ROSE   
Coverity7.5CHECKED_RETURNFinds inconsistencies in how function call return values are handled
Fortify SCA5.0  
Parasoft C/C++test9.5MRM-34 
Parasoft Insure++  Runtime detection

Related Vulnerabilities

The vulnerability in Adobe Flash [VU#159523] arises because Flash neglects to check the return value from calloc(). Even though calloc() returns NULL, Flash does not attempt to read or write to the return value. Instead, it attempts to write to an offset from the return value. Dereferencing NULL usually results in a program crash, but dereferencing an offset from NULL allows an exploit to succeed without crashing the program.

...