Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Search for vulnerabilities resulting from the violation of this rule on the CERT website.

Related Guidelines

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="edc48236-037d-44c5-aeb9-5183a5b0dce9"><ac:plain-text-body><![CDATA[

[[MITRE 2009

AA. Bibliography#MITRE 09]]

[CWE ID 111

http://cwe.mitre.org/data/definitions/111.html] "Direct Use of Unsafe JNI"

]]></ac:plain-text-body></ac:structured-macro>

Bibliography

<ac:structured-macro ac:name="unmigrated-wiki-markup

...

" ac:schema-version="1" ac:macro-id="0b42b522-d681-4b4e-8a5e-cbfff2a937eb"><ac:plain-text-body><![CDATA[

[[Fairbanks

...

2007

...

AA.

...

Bibliography#Fairbanks

...

07]]

...

 

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="9e032773-c61c-4be0-816d-bab8a6f1a741"><ac:plain-text-body><![CDATA[

[[JNI 2006

AA. Bibliography#JNI 06]]

 

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="989a7a45-61f7-4042-bfcd-35fa7a8e206f"><ac:plain-text-body><![CDATA[

[[Liang 1997

AA. Bibliography#Liang 97]]

 

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="a2fcfcf5-e478-42fa-8736-c2b8ee7615bd"><ac:plain-text-body><![CDATA[

[[Macgregor 1998

AA. Bibliography#Macgregor 98]]

Section 2.2.3,

...

Interfaces

...

and

...

Architectures

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="111d3da8-e22e-464b-b306-bddd83a65473"><ac:plain-text-body><![CDATA[

[[SCG 2007

AA. Bibliography#SCG 07]]

Guideline 3-3 Define wrappers around native methods

]]></ac:plain-text-body></ac:structured-macro>

...

SEC13-J. Do not allow unauthorized construction of classes in inaccessible packages      14. Platform Security (SEC)      SEC19-J. Do not rely on the default automatic signature verification provided by URLClassLoader and java.util.jar