Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: minor, see all previous

The recommendations suggested in the guideline CON13-J. Ensure that threads are properly terminatedDo not use Thread.stop() to terminate threads are insufficient to terminate a thread that is blocked on an operation involving network or file input-output (IO). Threads and tasks should provide callers with an explicit termination mechanism to prevent denial of service vulnerabilities.

...

This noncompliant code example uses a volatile done flag to indicate that it is safe to shut down the thread, as suggested in CON13-J. Ensure that threads are properly terminated. Do not use Thread.stop() to terminate threads. However, setting the flag does not terminate the thread because the thread is blocked on network IO as a consequence of using the readLine() method.

...