Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Added risk assessment; priority and level to be double-checked

...

The class objects will only be equal when they have the same class as defined in JVMSpec 99 and repeated above.

Risk Assessment

Incorrectly comparing classes using their names could give an attacker's class undesirable privileges.

Rule

Severity

Likelihood

Remediation Cost

Priority

Level

OBJ34-J

medium

probable

low

P4

L3

References

  1. Wiki Markup
    \[[JVMSpec 99|AA. Java References#JVMSpec 99]\] [§2.8.1 Class Names|http://java.sun.com/docs/books/jvms/second_edition/html/Concepts.doc.html]
  2. Wiki Markup
    \[[Christudas 05|AA. Java References#Christudas 05]\]
  3. Wiki Markup
    \[[Mcgraw 98|AA. Java References#Mcgraw 98]\]
  4. Wiki Markup
    \[[Wheeler 03|AA. Java References#Wheeler 03]\] [Java|http://www.dwheeler.com/secure-programs/Secure-Programs-HOWTO/java.html]