Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: in the 2nd CS, the pattern string was badly modified (on revision 39). reverted to the original pattern string.

...

CERT C Secure Coding Standard

MSC09-C. Character encoding - Use subset of ASCII for safety

CERT C++ Secure Coding Standard

MSC09-CPP. Character encoding - Use subset of ASCII for safety

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="b7d57766ef7344c7-731eb008-433f4bc7-a9699449-f639422f149eacb7fde834ef"><ac:plain-text-body><![CDATA[

[ISO/IEC TR 24772:2010

http://www.aitcnet.org/isai/]

Choice of filenames and other external identifiers [AJN]

]]></ac:plain-text-body></ac:structured-macro>

MITRE CWE

CWE-116. Improper encoding or escaping of output

...

ISO/IEC 646-1991

ISO 7-bit coded character set for information interchange

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="9261e10f0f00d412-dca937ae-49864405-b65aba0e-ce35510e5c0bc6ed5c0e3cba"><ac:plain-text-body><![CDATA[

[[Kuhn 2006

AA. References#Kuhn 06]]

UTF-8 and Unicode FAQ for UNIX/Linux

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="35f46cc164fb2833-11430aac-47ae4a4f-9ae2b22c-5a904cb5aa5c819134a55b7a"><ac:plain-text-body><![CDATA[

[[Wheeler 2003

AA. References#Wheeler03]]

5.4, File Names

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="7fec4f269251412c-7a228c6d-4a6a407f-899891b3-2f1cd2dade5ffe309d5a7669"><ac:plain-text-body><![CDATA[

[[VU#439395

AA. References#VU439395]]

]]></ac:plain-text-body></ac:structured-macro>

...

IDS04-J. Limit the size of files read from ZipInputStreamImage Added            IDS06-J. Exclude user input from format strings