Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: in the 2nd CS, the pattern string was badly modified (on revision 39). reverted to the original pattern string.

...

CERT C Secure Coding Standard

MSC09-C. Character encoding - Use subset of ASCII for safety

CERT C++ Secure Coding Standard

MSC09-CPP. Character encoding - Use subset of ASCII for safety

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="1413f63879e59b91-ec89f728-47aa4d55-ac51b1b5-e0900b2cf4914187937ec813"><ac:plain-text-body><![CDATA[

[ISO/IEC TR 24772:2010

http://www.aitcnet.org/isai/]

Choice of filenames and other external identifiers [AJN]

]]></ac:plain-text-body></ac:structured-macro>

MITRE CWE

CWE-116. Improper encoding or escaping of output

...

ISO/IEC 646-1991

ISO 7-bit coded character set for information interchange

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="66d288c16cb629ad-eb8c859f-48864616-89e693e9-1850e4f8f0bc557176c14143"><ac:plain-text-body><![CDATA[

[[Kuhn 2006

AA. References#Kuhn 06]]

UTF-8 and Unicode FAQ for UNIX/Linux

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="e26f8302e75fb92c-41e22ff5-41ac4d31-9f8691b0-8da27d5acd9a178fe6877d57"><ac:plain-text-body><![CDATA[

[[Wheeler 2003

AA. References#Wheeler03]]

5.4, File Names

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="796d3024392aa312-49c126e1-46984d0e-9210aabb-9ec40bf5ea6cdc61f3950629"><ac:plain-text-body><![CDATA[

[[VU#439395

AA. References#VU439395]]

]]></ac:plain-text-body></ac:structured-macro>

...

IDS04-J. Limit the size of files passed to read from ZipInputStream            IDS06-J. Exclude user input from format strings