Skip to main content
assistive.skiplink.to.breadcrumbs
assistive.skiplink.to.header.menu
assistive.skiplink.to.action.menu
assistive.skiplink.to.quick.search
Log in
Confluence
Spaces
Hit enter to search
Help
Online Help
Keyboard Shortcuts
Feed Builder
What’s new
Available Gadgets
About Confluence
Log in
SEI CERT C Coding Standard
Pages
Boards
Space shortcuts
Dashboard
Secure Coding Home
Android
C
C++
Java
Perl
Page tree
Browse pages
Configure
Space tools
View Page
A
t
tachments (0)
Page History
Page Information
View in Hierarchy
View Source
Export to PDF
Export to Word
Pages
…
SEI CERT C Coding Standard
2 Rules
Rule 10. Environment (ENV)
ENV33-C. Do not call system()
Page Information
Title:
ENV33-C. Do not call system()
Author:
Ben Tucker
Apr 27, 2007
Last Changed by:
Jill Britton
Apr 20, 2023
Tiny Link:
(useful for email)
https://wiki.sei.cmu.edu/confluence/x/MdYxBQ
Export As:
Word
·
PDF
Incoming Links
SEI CERT Oracle Coding Standard for Java (1)
Page:
IDS07-J. Sanitize untrusted data passed to the Runtime.exec() method
SEI CERT Perl Coding Standard (1)
Page:
IDS34-PL. Do not pass untrusted, unsanitized data to a command interpreter
SEI CERT C Coding Standard (3)
Page:
STR02-C. Sanitize data passed to complex subsystems
Page:
ENV03-C. Sanitize the environment when invoking external programs
Page:
FIO22-C. Close files before spawning processes
Hierarchy
Parent Page
Page:
Rule 10. Environment (ENV)
Labels
Global Labels (15)
review-dms
compass/rose
cwe-88
android-applicable
ptc
env
review-rcs
rose-complete
os-specific
posix
rule
review-ajb
cwe-78
klocwork
in-cpp
Recent Changes
Time
Editor
Apr 20, 2023 05:28
Jill Britton
View Changes
Nov 30, 2021 12:01
Jill Britton
View Changes
Aug 16, 2021 14:15
Robert Schiela
View Changes
Completed reference link text to C++ Coding Standard in Related Guidelines.
Apr 23, 2021 04:48
Jill Britton
View Changes
Apr 20, 2021 12:21
Jill Britton
View Page History
Outgoing Links
External Links (24)
msdn.microsoft.com/en-us/library/windows/desktop/aa363915(v…
cwe.mitre.org/
https://www.kb.cert.org/vulnotes/bymetric?searchview&query=…
https://msdn.microsoft.com/en-us/library/96ayss4b(v=vs.140)…
msdn.microsoft.com/en-us/library/windows/desktop/bb762188(v…
https://cwe.mitre.org/data/index.html676.html
https://www.mathworks.com/help/bugfinder/ref/certcruleenv33…
https://wiki.sei.cmu.edu/confluence/display/c/AA.+Bibliogra…
https://wiki.sei.cmu.edu/confluence/pages/viewpage.action?p…
https://wiki.sei.cmu.edu/confluence/pages/viewpage.action?p…
https://wiki.sei.cmu.edu/confluence/pages/viewpage.action?p…
pubs.opengroup.org/onlinepubs/9699919799/
https://wiki.sei.cmu.edu/confluence/display/java/SEI+CERT+O…
msdn.microsoft.com/en-us/library/windows/desktop/ms682425(v…
https://cwe.mitre.org/data/index.html
https://wiki.sei.cmu.edu/confluence/display/cplusplus/ENV02…
https://wiki.sei.cmu.edu/confluence/pages/viewpage.action?p…
https://wiki.sei.cmu.edu/confluence/display/java/IDS07-J.+S…
https://wiki.sei.cmu.edu/confluence/display/c/ENV03-C.+Sani…
https://wiki.sei.cmu.edu/confluence/pages/viewpage.action?p…
https://wiki.sei.cmu.edu/confluence/display/c/How+this+Codi…
https://wiki.sei.cmu.edu/confluence/display/c/AA.+Bibliogra…
https://www.sonarsource.com/products/codeanalyzers/sonarcfa…
cwe.mitre.org/data/definitions/88.html
SEI CERT C Coding Standard (32)
Page:
Helix QAC
Page:
Helix QAC_V
Page:
AA. Bibliography
Page:
RuleChecker
Page:
ENV03-C. Sanitize the environment when invoking external programs
Page:
Coverity_V
Page:
Klocwork_V
Page:
RuleChecker_V
Page:
WIN03-C. Understand HANDLE inheritance
Page:
LDRA
Page:
Klocwork
Page:
Astrée
Page:
Parasoft
Page:
Polyspace Bug Finder
Page:
PC-lint Plus_V
Page:
BB. Definitions
Page:
LDRA_V
Page:
CodeSonar
Page:
Polyspace Bug Finder_V
Page:
Parasoft_V
Page:
Axivion Bauhaus Suite
Page:
Clang_39_V
Page:
STR02-C. Sanitize data passed to complex subsystems
Page:
Astrée_V
Home page:
SEI CERT C Coding Standard
Page:
Axivion Bauhaus Suite_V
Page:
PC-lint Plus
Page:
Clang
Page:
FIO01-C. Be careful using functions that use file names for identification
Page:
CodeSonar_V
Page:
Rose
Page:
Coverity
Overview
Content Tools
{"serverDuration": 113, "requestCorrelationId": "174dcd9fdb51e294"}