Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: added taint capabilities

...

Recommendation

Severity

Likelihood

Remediation Cost

Priority

Level

IDS00-PL

medium

unlikely

medium

P4

L3

Automated Detection

Tool

Diagnostic

Notes
Taint mode

Insecure dependency in .*open

Only detects files open for writing.
Does not detect files open only for reading.

Related Guidelines

CERT C Secure Coding Standard: FIO02-C. Canonicalize path names originating from untrusted sources

...