<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="9937a844-3978-4037-bfd4-1df9af9657e5"><ac:parameter ac:name="">Apple 06</ac:parameter></ac:structured-macro>
[Apple 06] Apple, Inc. Secure Coding Guide, May 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="1755e26a-a2e5-4e01-9164-ee61cbbe0a4a"><ac:parameter ac:name="">Austin Group 08</ac:parameter></ac:structured-macro>
[Austin Group 08] "Draft Standard for Information Technology - Portable Operating System Interface (POSIX®) - Draft Technical Standard: Base Specifications, Issue 7," IEEE Unapproved Draft Std P1003.1 D5.1. Prepared by the Austin Group. New York: Institute of Electrical & Electronics Engineers, Inc., May 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="887e6cdd-0b10-4423-8590-2b772309aed7"><ac:parameter ac:name="">Banahan 03</ac:parameter></ac:structured-macro>
[Banahan 03] Banahan, Mike. The C Book, 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="61561bd8-27ed-4160-8c8a-c9c602a62ee2"><ac:parameter ac:name="">Beebe 05</ac:parameter></ac:structured-macro>
[Beebe 05] Beebe, Nelson H. F. Re: Remainder (%) operator and GCC, 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="e9b8ef5f-59a8-4ce6-9634-e571b17cd4cb"><ac:parameter ac:name="">Becker 08</ac:parameter></ac:structured-macro>
[Becker 08] Becker, Pete. Working Draft, Standard for Programming Language C++, April 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="8be4c62c-a975-42e4-9bb1-2f2f05a9e29f"><ac:parameter ac:name="">Black 07</ac:parameter></ac:structured-macro>
[Black 07] Paul E. Black, Michael Kass, Michael Koo. Source Code Security Analysis Tool Functional Specification Version 1.0. Special Publication 500-268. Information Technology Laboratory (ITL), Software Diagnostics and Conformance Testing Division, May 2007. http://samate.nist.gov/docs/source_code_security_analysis_spec_SP500-268.pdf
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="1278a245-805d-4490-b69e-7fbb3b615b5c"><ac:parameter ac:name="">Brainbell.com</ac:parameter></ac:structured-macro>
[Brainbell.com] Brainbell.com. Advice and Warnings for C Tutorials.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="f5e77810-2e27-4684-b90d-40211f30438c"><ac:parameter ac:name="">Bryant 03</ac:parameter></ac:structured-macro>
[Bryant 03] Bryant, Randal E., & O'Halloran, David. Computer Systems: A Programmer's Perspective. Prentice Hall, 2003 (ISBN 0-13-034074-X).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="7a468f3e-16c6-4748-9e2d-3591a24a831e"><ac:parameter ac:name="">Burch 06</ac:parameter></ac:structured-macro>
[Burch 06] Burch, Hal, Long, Fred, & Seacord, Robert C. Specifications for Managed Strings (CMU/SEI-2006-TR-006). Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University, 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="5e2c283d-ad78-4033-8944-a4478700c61d"><ac:parameter ac:name="">Callaghan 95</ac:parameter></ac:structured-macro>
[Callaghan 95] Callaghan, B., Pawlowski, B., & Staubach, P. IETF RFC 1813 NFS Version 3 Protocol Specification, June 1995.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="e7525990-6016-4be5-86b1-041fea573551"><ac:parameter ac:name="">CERT 06a</ac:parameter></ac:structured-macro>
[CERT 06a] CERT/CC. CERT/CC Statistics 1988---2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="54aa0aef-beed-4428-a872-105143ea829e"><ac:parameter ac:name="">CERT 06b</ac:parameter></ac:structured-macro>
[CERT 06b] CERT/CC. US-CERT's Technical Cyber Security Alerts.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="102770f4-6e77-4d19-8441-6df1de5edead"><ac:parameter ac:name="">CERT 06c</ac:parameter></ac:structured-macro>
[CERT 06c] CERT/CC. Secure Coding web site.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="74579f7c-8ad9-4b3c-9eeb-dbac09f70634"><ac:parameter ac:name="">Chen 02</ac:parameter></ac:structured-macro>
[Chen 02] Chen, H., Wagner, D., & Dean, D. Setuid Demystified USENIX Security Symposium, 2002.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="b8307578-ff21-428e-b962-7217539a7890"><ac:parameter ac:name="">Corfield 93</ac:parameter></ac:structured-macro>
[Corfield 93] Corfield, Sean A. "Making String Literals 'const'," November 1993.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="6a88b55e-d797-4e4d-8828-c60cf9713329"><ac:parameter ac:name="">Coverity 07</ac:parameter></ac:structured-macro>
[Coverity 07] Coverity Prevent User's Manual (3.3.0), 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="817301a4-78db-41be-a9e4-3150c5bf0171"><ac:parameter ac:name="">CVE</ac:parameter></ac:structured-macro>
[CVE] Common Vulnerabilities and Exposures.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="49ce7850-dfef-40a1-b320-e0a13821db2a"><ac:parameter ac:name="">CPPReference</ac:parameter></ac:structured-macro>
[C++ Reference] Standard C Library, General C+, C+ Standard Template Library
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="8ea236b8-3720-4188-b596-305a4c3bcb11"><ac:parameter ac:name="">Dewhurst 02</ac:parameter></ac:structured-macro>
[Dewhurst 02] Dewhurst, Stephen C. C++ Gotchas: Avoiding Common Problems in Coding and Design. Boston: Addison-Wesley Professional, 2002.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="37c58b83-89b4-40da-a534-45a654284091"><ac:parameter ac:name="">Dewhurst 05</ac:parameter></ac:structured-macro>
[Dewhurst 05] Dewhurst, Stephen C. C++ Common Knowledge: Essential Intermediate Programming. Boston, MA: Addison-Wesley Professional, 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="587c7b3d-3e74-4eaf-ae2c-166562985b5e"><ac:parameter ac:name="">DHS 06</ac:parameter></ac:structured-macro>
[DHS 06] U.S. Department of Homeland Security. Build Security In.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="d8c9aa97-1ad9-4600-9cdb-7d9e773d6757"><ac:parameter ac:name="">DISA 2008</ac:parameter></ac:structured-macro>
[DISA 2008] DISA. Application Security and Development Security Technical Implementation Guide, Version 2, Release 1. July, 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="509ba2b1-a7b8-4de9-8cb7-7643b81ca88b"><ac:parameter ac:name=""> DOD 5220</ac:parameter></ac:structured-macro>
[DOD 5220] U.S. Department of Defense. DoD Standard 5220.22-M (Word document).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="096c3cab-b242-4fdf-8555-a94087113125"><ac:parameter ac:name="">Dowd 06</ac:parameter></ac:structured-macro>
[Dowd 06] Dowd, M., McDonald, J., & Schuh, J. The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities. Boston: Addison-Wesley, 2006. See http://taossa.com for updates and errata.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="b7293490-713c-4c6e-8ea2-aac055d8bb20"><ac:parameter ac:name="">Drepper 06</ac:parameter></ac:structured-macro>
[Drepper 06] Drepper, Ulrich. Defensive Programming for Red Hat Enterprise Linux (and What To Do If Something Goes Wrong), May 3, 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="3ca967ea-ab86-4b14-a38a-49528fd80c67"><ac:parameter ac:name="">Eckel 07</ac:parameter></ac:structured-macro>
[Eckel 07] Eckel, Bruce. Thinking in C++ Volume 2, January 25, 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="6037a607-8af2-4600-8adc-d78d9ec9eeb7"><ac:parameter ac:name="">ECTC 98</ac:parameter></ac:structured-macro>
[ECTC 98] Embedded C++ Technical Committee. The Embedded C++ Programming Guide Lines, Version WP-GU-003. January 6, 1998.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="fc6e6037-0950-430f-9fda-7b2995785d68"><ac:parameter ac:name="">Eide and Regehr</ac:parameter></ac:structured-macro>
[Eide and Regehr] "Volatiles are miscompiled, and what to do about it" Eide E., Regehr J. 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="85eac1fd-52b4-4d14-9d49-2505d5ff47f3"><ac:parameter ac:name="">Finlay 03</ac:parameter></ac:structured-macro>
[Finlay 03] Finlay, Ian A. CERT Advisory CA-2003-16, Buffer Overflow in Microsoft RPC. CERT/CC, July 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="50f2a1e4-6c30-4c60-affa-cbfe937e6566"><ac:parameter ac:name="">Fisher 99</ac:parameter></ac:structured-macro>
[Fisher 99] Fisher, David & Lipson, Howard. "Emergent Algorithms - A New Method for Enhancing Survivability in Unbounded Systems." Proceedings of the 32nd Annual Hawaii International Conference on System Sciences (HICSS-32). Maui, HI, January 5-8, 1999.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="2f3c46d7-f49b-431c-8658-b1dd48641af9"><ac:parameter ac:name="">Flake 06</ac:parameter></ac:structured-macro>
[Flake 06] Flake, Halvar. "Attacks on uninitialized local variables." Black Hat Federal 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="f1e0a54d-140d-4c43-b2bc-605151a7b3ea"><ac:parameter ac:name="">Fortify 06</ac:parameter></ac:structured-macro>
[Fortify 06] Fortify Software Inc. Fortify Taxonomy: Software Security Errors, 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="21c4d0ba-6cf6-4149-be59-3081b561189b"><ac:parameter ac:name="">FSF 05</ac:parameter></ac:structured-macro>
[FSF 05] Free Software Foundation. GCC online documentation, 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="79d27e0b-c6cb-472c-a341-43a09e7ec964"><ac:parameter ac:name="">Garfinkel 96</ac:parameter></ac:structured-macro>
[Garfinkel 96] Garfinkel, Simson & Spafford, Gene. Practical UNIX & Internet Security, 2nd Edition. Sebastopol, CA: O'Reilly Media, April 1996 (ISBN 1-56592-148-8).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="5fe9724d-e4a1-4b07-a18d-69306c18c8ef"><ac:parameter ac:name="">GNU Pth</ac:parameter></ac:structured-macro>
[GNU Pth] Engelschall, Ralf S. GNU Portable Threads, 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="2e6b134f-0d7e-4f20-9a36-19fc5d15d4f2"><ac:parameter ac:name="">Goldberg 91</ac:parameter></ac:structured-macro>
[Goldberg 91] Goldberg, David. What Every Computer Scientist Should Know About Floating-Point Arithmetic. Sun Microsystems, March 1991.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="957022cc-a918-453d-9e4f-74ff316d3c6f"><ac:parameter ac:name="">Goodin 2009</ac:parameter></ac:structured-macro>
[Goodin 2009] Dan Goodin. Clever attack exploits fully-patched Linux kernel The Register. July 2009.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="a85f22a2-68b7-455b-a594-0e8b6c1f6103"><ac:parameter ac:name="">Gough 2005</ac:parameter></ac:structured-macro>
[Gough 2005] Gough, Brian J. An Introduction to GCC. Network Theory Ltd, Revised August 2005 (ISBN 0-9541617-9-3).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="77f65c82-7aab-4df8-ba90-9e9337db849f"><ac:parameter ac:name="">Graf 03</ac:parameter></ac:structured-macro>
[Graff 03] Graff, Mark G. & Van Wyk, Kenneth R. Secure Coding: Principles and Practices. Cambridge, MA: O'Reilly, 2003 (ISBN 0596002424).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="76bc2875-e22a-4409-859c-8500acc4efc4"><ac:parameter ac:name="">Greenman 97</ac:parameter></ac:structured-macro>
[Greenman 97] Greenman, David. serious security bug in wu-ftpd v2.4. BUGTRAQ Mailing List (bugtraq@securityfocus.com), January 2, 1997.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="6d7c9940-0f4c-431a-98fd-d3bb4c63d9fb"><ac:parameter ac:name="">Griffiths 06</ac:parameter></ac:structured-macro>
[Griffiths 06] Griffiths, Andrew. "Clutching at straws: When you can shift the stack pointer."
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="f3d7f938-0490-494b-80f8-39b0617a410e"><ac:parameter ac:name="">Gutmann 96</ac:parameter></ac:structured-macro>
[Gutmann 96] Gutmann, Peter. Secure Deletion of Data from Magnetic and Solid-State Memory, July 1996.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="2f74df9c-4acb-4b05-9184-08bb4d9746a6"><ac:parameter ac:name="">Haddad 05</ac:parameter></ac:structured-macro>
[Haddad 05] Haddad, Ibrahim. "Secure Coding in C and C++: An interview with Robert Seacord, senior vulnerability analyst at CERT." Linux World Magazine, November 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="64e58450-9552-4cb0-8a0d-bf9b76a4774f"><ac:parameter ac:name="">Hatton 95</ac:parameter></ac:structured-macro>
[Hatton 95] Hatton, Les. Safer C: Developing Software for High-Integrity and Safety-Critical Systems. New York: McGraw-Hill Book Company, 1995 (ISBN 0-07-707640-0).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="c8126bfd-3f8b-45f4-b39e-fe74b8c4e041"><ac:parameter ac:name="">Hatton 03</ac:parameter></ac:structured-macro>
[Hatton 03] Hatton, Les. EC-: A measurement based safer subset of ISO C suitable for embedded system development. November 5, 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="e84458fc-0c8a-4cc6-b8c3-67543ed72a31"><ac:parameter ac:name="">Henricson 92</ac:parameter></ac:structured-macro>
[Henricson 92] Henricson, Mats, & Nyquist, Erik. Programming in C++, Rules and Recommendations. Ellemtel Telecommunication Systems Laboratories, 1992.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="ee7a9b11-d4fb-4521-9166-8bb26faa1318"><ac:parameter ac:name="">Horton 90</ac:parameter></ac:structured-macro>
[Horton 90] Horton, Mark R. Portable C Software. Upper Saddle River, NJ: Prentice-Hall, Inc., 1990 (ISBN:0-13-868050-7).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="5027d705-732c-49f9-98fd-45610e7a771f"><ac:parameter ac:name="">Howard 02</ac:parameter></ac:structured-macro>
[Howard 02] Howard, Michael, & LeBlanc, David C. Writing Secure Code, 2nd ed. Redmond, WA:. Microsoft Press, December 2002.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="b5c991a2-7aba-4a46-b9ee-d28375e6a7be"><ac:parameter ac:name="">HP 03</ac:parameter></ac:structured-macro>
[HP 03] Tru64 UNIX: Protecting Your System Against File Name Spoofing Attacks. Houston, TX: Hewlett-Packard Company, January 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="7cab0b71-460b-431d-8bf5-b13583562ede"><ac:parameter ac:name="">IEC 60812 2006</ac:parameter></ac:structured-macro>
[IEC 60812 2006] Analysis techniques for system reliability - Procedure for failure mode and effects analysis (FMEA), 2nd ed. (IEC 60812). IEC, January 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="a028a9cc-63c4-4d3b-b79e-2e70791d01d4"><ac:parameter ac:name="">IEC 61508 4</ac:parameter></ac:structured-macro>
[IEC 61508-4] Functional safety of electrical/electronic/programmable electronic safety-related systems - Part 4: Definitions and abbreviations, 1998.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="0f9e5a6c-d7ee-4cef-9eba-a9d2e579a633"><ac:parameter ac:name="">IEEE Std 610.12 1990</ac:parameter></ac:structured-macro>
[IEEE Std 610.12 1990] IEEE Standard Glossary of Software Engineering Terminology, September 1990.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="2a7594c2-77d1-4a69-8b0d-775a7b92ddc5"><ac:parameter ac:name="">IEEE 754 2006</ac:parameter></ac:structured-macro>
[IEEE 754 2006] IEEE. Standard for Binary Floating-Point Arithmetic (IEEE 754-1985), 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="cda0c49a-f3d1-48b5-bd06-1d835f78f517"><ac:parameter ac:name="">ilja 06</ac:parameter></ac:structured-macro>
[IEEE 1003.1, 2004] IEEE. The Open Group Base Specifications Issue 6 IEEE Std 1003.1, 2004 Edition
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="717b88e3-d81a-4265-bcdb-dba69a9f9130"><ac:parameter ac:name="">IEEE 1003</ac:parameter></ac:structured-macro>
[ilja 06] ilja. "readlink abuse." ilja's blog, August 13, 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="db543447-d7cd-416c-9c42-31517a4f25dd"><ac:parameter ac:name="">Intel 01</ac:parameter></ac:structured-macro>
[Intel 01] Intel Corp. _Floating-Point IEEE Filter for Microsoft* Windows* 2000 on the Intel® Itanium⢠Architecture_, March 2001.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="4a724423-046e-456b-a6cd-4c4a44ac299d"><ac:parameter ac:name="">Internet Society 00</ac:parameter></ac:structured-macro>
[Internet Society 00] The Internet Society. Internet Security Glossary (RFC 2828), 2000.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="017caa23-77cf-420a-9a67-ead1585a731b"><ac:parameter ac:name="">ISO/IEC 646-1991</ac:parameter></ac:structured-macro>
[ISO/IEC 646:1991] ISO/IEC. Information technology: ISO 7-bit coded character set for information interchange (ISO/IEC 646-1991). Geneva, Switzerland: International Organization for Standardization, 1991.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="afd5ae63-7eeb-4343-b580-53e342b7f29f"><ac:parameter ac:name="">ISO/IEC 9945-2003</ac:parameter></ac:structured-macro>
[ISO/IEC 9945:2003] ISO/IEC 9945:2003 (including Technical Corrigendum 1), Information technology — Programming languages, their environments and system software interfaces — Portable Operating System Interface (POSIX®).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="04cae52e-538e-45f7-827c-7c1bd91b35ec"><ac:parameter ac:name="">ISO/IEC 9899-1999</ac:parameter></ac:structured-macro>
[ISO/IEC 9899:1999] ISO/IEC. Programming Languages---C, 2nd ed (ISO/IEC 9899:1999). Geneva, Switzerland: International Organization for Standardization, 1999.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="c1c9d993-6eaa-4cc4-8625-f3ce588ba261"><ac:parameter ac:name="">ISO/IEC 10646-2003</ac:parameter></ac:structured-macro>
[ISO/IEC 10646:2003] Information technology - Universal Multiple-Octet Coded Character Set (UCS) (ISO/IEC 10646:2003). Geneva, Switzerland: International Organization for Standardization, 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="09bfd990-22b7-4bcb-a88d-46a584653226"><ac:parameter ac:name="">ISO/IEC 14882-2003</ac:parameter></ac:structured-macro>
[ISO/IEC 14882:2003] ISO/IEC. Programming Languages — C++, Second Edition (ISO/IEC 14882-2003). Geneva, Switzerland: International Organization for Standardization, 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="0305c4a3-a426-4ce0-a98d-bdf37ed8e35c"><ac:parameter ac:name="">ISO/IEC 23360-1-2006</ac:parameter></ac:structured-macro>
[ISO/IEC 23360-1:2006] Linux Standard Base (LSB) core specification 3.1 - Part 1: Generic specification
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="a6f48a18-ae79-4d44-b7a7-4a6572f4a978"><ac:parameter ac:name="">ISO/IEC 03</ac:parameter></ac:structured-macro>
[ISO/IEC 03] ISO/IEC. Rationale for International Standard — Programming Languages — C, Revision 5.10. Geneva, Switzerland: International Organization for Standardization, April 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="8baff743-0ed1-4a92-858a-45aa8e116158"><ac:parameter ac:name="">ISO/IEC JTC1/SC22/WG11</ac:parameter></ac:structured-macro>
[ISO/IEC JTC1/SC22/WG11] ISO/IEC. Binding Techniques (ISO/IEC JTC1/SC22/WG11), 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="14f3b866-b549-4080-933c-3393fc96b41a"><ac:parameter ac:name="">ISO/IEC DTR 24732</ac:parameter></ac:structured-macro>
[ISO/IEC DTR 24732] ISO/IEC JTC1 SC22 WG14 N1290. Extension for the programming language C to support decimal floating-point arithmetic, March 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="5581c563-895a-48b5-906c-ccdf1727a996"><ac:parameter ac:name="">ISO/IEC PDTR 24731-2-2007</ac:parameter></ac:structured-macro>
[ISO/IEC PDTR 24731-2] Extensions to the C Library, — Part II: Dynamic Allocation Functions, August 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="660ff848-1f7b-4c87-ae68-0f868b517edf"><ac:parameter ac:name="">ISO/IEC PDTR 24772</ac:parameter></ac:structured-macro>
[ISO/IEC PDTR 24772] ISO/IEC PDTR 24772. Information Technology — Programming Languages — Guidance to Avoiding Vulnerabilities in Programming Languages through Language Selection and Use, March 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="4fd9e423-0572-44fa-b297-b06f89f5e627"><ac:parameter ac:name="">ISO/IEC TR 24731-1-2007</ac:parameter></ac:structured-macro>
[ISO/IEC TR 24731-1:2007] ISO/IEC TR 24731. Extensions to the C Library, — Part I: Bounds-checking interfaces. Geneva, Switzerland: International Organization for Standardization, April 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="4897e18b-f3d9-4da9-8504-4029b5c69ab9"><ac:parameter ac:name="">Jack 07</ac:parameter></ac:structured-macro>
[Jack 07] Jack, Barnaby. Vector Rewrite Attack, May 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="780d271c-4917-4517-9855-dfe9eef3fcfa"><ac:parameter ac:name="">Jones 04</ac:parameter></ac:structured-macro>
[Jones 04] Jones, Nigel. "Learn a new trick with the offsetof() macro." Embedded Systems Programming, March 2004.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="3b1e2824-e538-4a70-be0a-bfc0836bb7de"><ac:parameter ac:name="">Jones 08</ac:parameter></ac:structured-macro>
[Jones 08] Jones, Derek M. The New C Standard: An economic and cultural commentary. Knowledge Software Ltd., 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="db28ed0f-0522-45db-99f7-bc18f083d9f1"><ac:parameter ac:name="">Jones 09</ac:parameter></ac:structured-macro>
[Jones 09] Jones, Larry. WG14 N1401 Committee Draft ISO/IEC 9899:201x. September 28, 2009.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="5719ba64-0e2d-49c2-ba13-634ed4c4032c"><ac:parameter ac:name="">Keaton 09</ac:parameter></ac:structured-macro>
[Keaton 09] David Keaton, Thomas Plum, Robert C. Seacord, David Svoboda, Alex Volkovitsky, Timothy Wilson. As-if Infinitely Ranged Integer Model. CMU/SEI-2009-TN-023. July, 2009.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="0ee29994-f205-4d41-943c-f348f3dae1f4"><ac:parameter ac:name="">Keil 08</ac:parameter></ac:structured-macro>
[Keil 08] Keil, an ARM Company. "Floating Point Support." RealView Libraries and Floating Point Support Guide, 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="b14229b3-91ca-4a1b-bc4d-8fa5b1cf0028"><ac:parameter ac:name="">Kennaway 00</ac:parameter></ac:structured-macro>
[Kennaway 00] Kennaway, Kris. Re: /tmp topic, December 2000.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="14aa3397-dd76-4b46-b0be-e1e5072a2a0a"><ac:parameter ac:name="">Kernighan 88</ac:parameter></ac:structured-macro>
[Kernighan 88] Kernighan , Brian W., & Ritchie, Dennis M. The C Programming Language, 2nd ed. Englewood Cliffs, NJ: Prentice-Hall, 1988.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="c81f1669-7fec-4580-9391-c544d635c61e"><ac:parameter ac:name="">Kettle 02</ac:parameter></ac:structured-macro>
[Kettlewell 02] Kettlewell, Richard. C Language Gotchas, February 2002.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="c83bad6c-628b-4b4a-89ed-ab9fa1c2e24e"><ac:parameter ac:name="">Kettle 03</ac:parameter></ac:structured-macro>
[Kettlewell 03] Kettlewell, Richard. Inline Functions In C, March 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="3d459e9c-901c-429e-aa3c-f04959ac6e06"><ac:parameter ac:name="">Kirch-Prinz 02</ac:parameter></ac:structured-macro>
[Kirch-Prinz 02] Kirch-Prinz, Ulla & Prinz, Peter. C Pocket Reference. Sebastopol, CA: O'Reilly, November 2002 (ISBN: 0-596-00436-2).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="25e89977-c3f4-454d-83bc-5548c668d96b"><ac:parameter ac:name="">Klarer 04</ac:parameter></ac:structured-macro>
[Klarer 04] Klarer, R., Maddock, J., Dawes, B. & Hinnant, H. "Proposal to Add Static Assertions to the Core Language (Revision 3)." ISO C++ committee paper ISO/IEC JTC1/SC22/WG21/N1720, October 2004. Available at http://www.open-std.org/jtc1/sc22/wg21/docs/papers/2004/n1720.html.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="2fcab31a-1ca7-486d-9511-d5e75a801f7c"><ac:parameter ac:name="">Klein 02</ac:parameter></ac:structured-macro>
[Klein 02] Klein, Jack. Bullet Proof Integer Input Using strtol(), 2002.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="eb677eba-ca3b-4e61-818a-95c8d305876d"><ac:parameter ac:name="">Koenig 89</ac:parameter></ac:structured-macro>
[Koenig 89] Koenig, Andrew. C Traps and Pitfalls. Addison-Wesley Professional, January 1, 1989.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="470e773a-60c7-4af1-8b43-81f7d640d071"><ac:parameter ac:name="">Kuhn 06</ac:parameter></ac:structured-macro>
[Kuhn 06] Kuhn, Markus. UTF-8 and Unicode FAQ for Unix/Linux, 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="e0fa9b49-e5fa-4d7f-8d02-7d9e008453cd"><ac:parameter ac:name="">Lai 06</ac:parameter></ac:structured-macro>
[Lai 06] Lai, Ray. "Reading Between the Lines." OpenBSD Journal, October 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="6e57dfd3-f44c-485b-97b8-d6a212c26703"><ac:parameter ac:name="">Lewis 06</ac:parameter></ac:structured-macro>
[Lewis 06] Lewis, Richard. "Security Considerations When Handling Sensitive Data." Posted on the Application Security by Richard Lewis blog October 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="974dde7d-a10b-4974-808c-861d6d89865b"><ac:parameter ac:name="">Linux 08</ac:parameter></ac:structured-macro>
[Linux 08] Linux Programmer's Manual, October 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="768597d3-1897-47b6-bc44-67498fd35142"><ac:parameter ac:name="">Lions 96</ac:parameter></ac:structured-macro>
[Lions 96] Lions, J. L. ARIANE 5 Flight 501 Failure Report. Paris, France: European Space Agency (ESA) & National Center for Space Study (CNES) Inquiry Board, July 1996.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="01673620-b19a-4bc2-bf98-29a1031328d0"><ac:parameter ac:name="">Lipson 00</ac:parameter></ac:structured-macro>
[Lipson 00] Lipson, Howard & Fisher, David. "Survivability: A New Technical and Business Perspective on Security," 33-39. Proceedings of the 1999 New Security Paradigms Workshop. Caledon Hills, Ontario, Canada, Sept. 22-24, 1999. New York: Association for Computing Machinery, 2000.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="47d425c3-7c9b-4cbc-a08e-b591225b8725"><ac:parameter ac:name="">Lipson 06</ac:parameter></ac:structured-macro>
[Lipson 06] Lipson, Howard. Evolutionary Systems Design: Recognizing Changes in Security and Survivability Risks (CMU/SEI-2006-TN-027). Pittsburgh, PA: Software Engineering Institute, Carnegie Mellon University, 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="637f981f-cf41-4815-8ae3-f16de397c1b1"><ac:parameter ac:name="">Lipson 2009</ac:parameter></ac:structured-macro>
[Liu 2009] Likai Liu. Making NULL-pointer reference legal, Life of a Computer Science Student, January, 2009.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="df21c5f0-98b4-4bbe-85a5-29bb0236094e"><ac:parameter ac:name="">Lockheed Martin 05</ac:parameter></ac:structured-macro>
[Lockheed Martin 05] Lockheed Martin. "Joint Strike Fighter Air Vehicle C++ Coding Standards for the System Development and Demonstration Program." Document Number 2RDU00001 Rev C., December 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="9e14f8be-ffa2-4286-a785-2e00e358243a"><ac:parameter ac:name="">Loosemore 07</ac:parameter></ac:structured-macro>
[Loosemore 07] Loosemore, Sandra, Stallman, Richard M., McGrath, Roland, Oram, Andrew, & Drepper, Ulrich. The GNU C Library Reference Manual, Edition 0.11, September 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="36c46e1b-363b-40a6-8a6d-073bbe41f063"><ac:parameter ac:name="">McCluskey 01</ac:parameter></ac:structured-macro>
[McCluskey 01] flexible array members and designators in C9X ;login:, July 2001, Volume 26, Number 4, p. 29---32.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="a5f253c3-6bc9-4ef2-bf4f-9790efd884cc"><ac:parameter ac:name="">Mell 07</ac:parameter></ac:structured-macro>
[Mell 07] P. Mell, K. Scarfone, and S. Romanosky, "A Complete Guide to the Common Vulnerability Scoring System Version 2.0", FIRST, June 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="cf74cb69-b3ed-4cc1-bf26-56a28cd383f6"><ac:parameter ac:name="">mercy 06</ac:parameter></ac:structured-macro>
[mercy] mercy. Exploiting Uninitialized Data, January 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="3d97a929-f2c1-41de-ab73-dfb1b9120d5d"><ac:parameter ac:name="">Meyers 2004</ac:parameter></ac:structured-macro>
[Meyers 2004] Randy Meyers. Limited size_t WG14 N1080. September, 2004.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="e81a7bad-a2a9-4152-9b8b-d2656cc48a19"><ac:parameter ac:name="">Microsoft 03</ac:parameter></ac:structured-macro>
[Microsoft 03] Microsoft Security Bulletin MS03-026, "Buffer Overrun In RPC Interface Could Allow Code Execution (823980)," September 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="0baa347d-63d0-4f59-a08e-07490e8ab5d7"><ac:parameter ac:name="">Microsoft 07</ac:parameter></ac:structured-macro>
[Microsoft 07] C Language Reference, 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="6d424d2e-9ff1-47cb-8707-fdad5e01ca7c"><ac:parameter ac:name="">Miller 99</ac:parameter></ac:structured-macro>
[Miller 99] Todd C. Miller and Theo de Raadt. strlcpy and strlcat - Consistent, Safe, String Copy and Concatenation. In Proceedings of the FREENIX Track, 1999 USENIX Annual Technical Conference.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="05f24356-96a8-4af9-9f6b-4d40940ceba1"><ac:parameter ac:name="">Miller 04</ac:parameter></ac:structured-macro>
[Miller 04] Miller, Mark C., Reus, James F., Matzke, Robb P., Koziol, Quincey A., & Cheng, Albert P. "Smart Libraries: Best SQE Practices for Libraries with an Emphasis on Scientific Computing." Proceedings of the Nuclear Explosives Code Developer's Conference, December 2004.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="ef7bb12e-eda4-4ac5-b837-9293c6001da5"><ac:parameter ac:name="">MISRA 04</ac:parameter></ac:structured-macro>
[MISRA 04] MISRA Limited. "MISRA C: 2004 Guidelines for the Use of the C Language in Critical Systems." Warwickshire, UK: MIRA Limited, October 2004 (ISBN 095241564X).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="41b53aa8-2c1a-4369-8906-4744ce835c53"><ac:parameter ac:name="">MISRA 08</ac:parameter></ac:structured-macro>
[MISRA 08] MIRA Limited. "MISRA C++: 2008 "Guidelines for the Use of the C++ Language in Critical Systems", ISBN 978-906400-03-3 (paperback), ISBN 978-906400-04-0 (PDF), June 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="6acd989f-9bf9-4c7b-bcf8-5435846ab121"><ac:parameter ac:name="">MIT 04</ac:parameter></ac:structured-macro>
[MIT 04] MIT. "MIT krb5 Security Advisory 2004-002, 2004.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="549b197b-d1b9-4b66-8b1f-043645845963"><ac:parameter ac:name="">MIT 05</ac:parameter></ac:structured-macro>
[MIT 05] MIT. "MIT krb5 Security Advisory 2005-003, 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="88e91eaa-0937-4d05-be64-48649c4eb0e9"><ac:parameter ac:name="">MITRE 07</ac:parameter></ac:structured-macro>
[MITRE 07] MITRE. Common Weakness Enumeration, Draft 9, April 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="4e77a2eb-6ca3-4453-9653-914d90b42fd4"><ac:parameter ac:name="">MSDN</ac:parameter></ac:structured-macro>
[MSDN] Microsoft Developer Network.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="28879d93-5950-42b5-9ad5-850a8a7c59e3"><ac:parameter ac:name="">Murenin 07</ac:parameter></ac:structured-macro>
[Murenin 07] Murenin, Constantine A. "cnst: 10-year-old pointer-arithmetic bug in make(1) is now gone, thanks to malloc.conf and some debugging," June 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="0372b65c-13db-468d-85a2-42a3df9fe35a"><ac:parameter ac:name="">NAI 98</ac:parameter></ac:structured-macro>
[NAI 98] Network Associates Inc. Bugtraq: Network Associates Inc. Advisory (OpenBSD), 1998.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="5a7a2272-017d-48fc-876d-1bfe2841f033"><ac:parameter ac:name="">NASA-GB-1740.13</ac:parameter></ac:structured-macro>
[NASA-GB-1740.13] NASA Glenn Research Center, Office of Safety Assurance Technologies. NASA Software Safety Guidebook (NASA-GB-1740.13).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="cb5901a0-41cf-4f30-b474-85f896560ae2"><ac:parameter ac:name="">NIST 06</ac:parameter></ac:structured-macro>
[NIST 06] NIST. SAMATE Reference Dataset, 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="47ae0ff3-c002-4af0-9e11-50727eb7da17"><ac:parameter ac:name="">OpenBSD</ac:parameter></ac:structured-macro>
[OpenBSD] Berkley Software Design, Inc. Manual Pages, June 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="3b6131b1-f528-42ba-9541-4351e11d7c63"><ac:parameter ac:name="">Open Group 97a</ac:parameter></ac:structured-macro>
[Open Group 97a] The Open Group. The Single UNIX® Specification, Version 2, 1997.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="0e6296c8-2a31-4f38-8a64-63a62f4b19dd"><ac:parameter ac:name="">Open Group 97b</ac:parameter></ac:structured-macro>
[Open Group 97b] The Open Group. Go Solo 2---The Authorized Guide to Version 2 of the Single UNIX Specification, May 1997.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="0ebf320f-e5fe-4bca-b8d8-c399643d1864"><ac:parameter ac:name="">Open Group 04</ac:parameter></ac:structured-macro>
[Open Group 04] The Open Group and the IEEE. The Open Group Base Specifications Issue 6, IEEE Std 1003.1, 2004 Edition, 2004.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="b10a6868-86ae-46ab-8621-f3eca7461f0d"><ac:parameter ac:name="">OWASP Double Free</ac:parameter></ac:structured-macro>
[OWASP Double Free] Open Web Application Security Project, "Double Free."
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="793fede7-192c-4f85-9ee4-ce8adcc143ba"><ac:parameter ac:name="">OWASP Freed Memory</ac:parameter></ac:structured-macro>
[OWASP Freed Memory] Open Web Application Security Project, "Using freed memory."
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="0ddd352d-1ceb-4c31-adc0-00c832423eb2"><ac:parameter ac:name="">Pethia 03</ac:parameter></ac:structured-macro>
[Pethia 03] Pethia, Richard D. "Viruses and Worms: What Can We Do About Them?" September 10, 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="40bb6108-2c54-4905-bd3b-4a62cdc36733"><ac:parameter ac:name="">Pfaff 04</ac:parameter></ac:structured-macro>
[Pfaff 04] Pfaff, Ken Thompson. "Casting (time_t)(-1)." Google Groups comps.lang.c, March 2, 2004.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="087120c9-577c-45cf-b376-136164539113"><ac:parameter ac:name="">Pike 93</ac:parameter></ac:structured-macro>
[Pike 93] Pike, Rob & Thompson, Ken. "Hello World." Proceedings of the USENIX Winter 1993 Technical Conference, San Diego, CA, January 25--29, 1993, pp. 43--50.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="ba95c40d-81db-46f1-a378-ce5bc1810468"><ac:parameter ac:name="">Plakosh 05</ac:parameter></ac:structured-macro>
[Plakosh 05] Plakosh, Dan. Consistent Memory Management Conventions, 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="ed7e083e-4c02-4b7b-be7b-89c1daf55e42"><ac:parameter ac:name="">Plum 85</ac:parameter></ac:structured-macro>
[Plum 85] Plum, Thomas. Reliable Data Structures in C. Kamuela, HI: Plum Hall, Inc., 1985 (ISBN 0-911537-04-X).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="76b65657-e645-4d8b-ac2e-d81f398e4a29"><ac:parameter ac:name="">Plum 89</ac:parameter></ac:structured-macro>
[Plum 89] Plum, Thomas, & Saks, Dan. C Programming Guidelines, 2nd ed. Kamuela, HI: Plum Hall, 1989 (ISBN 0911537074).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="e840ff1c-5c49-497e-976b-55f55c9562b8"><ac:parameter ac:name="">Plum 91</ac:parameter></ac:structured-macro>
[Plum 91] Plum, Thomas. C++ Programming. Kamuela, HI: Plum Hall, 1991 (ISBN 0911537104).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="f283d934-87fd-4785-ae0d-c07591604442"><ac:parameter ac:name="">Plum 08</ac:parameter></ac:structured-macro>
[Plum 08] Plum, Thomas. Static Assertions. June, 2008. http://www.open-std.org/jtc1/sc22/wg14/www/docs/n1330.pdf
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="3c6ed730-b4e5-4fc0-ae1e-8848edf218ff"><ac:parameter ac:name="">Redwine 06</ac:parameter></ac:structured-macro>
[Redwine 06] Redwine, Samuel T., Jr., ed. Secure Software Assurance: A Guide to the Common Body of Knowledge to Produce, Acquire, and Sustain Secure Software Version 1.1. U.S. Department of Homeland Security, September 2006. See Software Assurance Common Body of Knowledge on Build Security In.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="84331bb9-a374-4eda-94c2-8c39f32f699b"><ac:parameter ac:name="">RUS-CERT</ac:parameter></ac:structured-macro>
[RUS-CERT] RUS-CERT Advisory 2002-08:02, "Flaw in calloc and similar routines," 2002.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="e684bb5e-f324-4860-b185-4696800fea52"><ac:parameter ac:name="">Saltzer 74</ac:parameter></ac:structured-macro>
[Saltzer 74] Saltzer, J. H. Protection and the Control of Information Sharing in Multics. Communications of the ACM 17, 7 (July 1974): 388---402.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="14d593e1-892f-4e72-bf42-aa7f965932fd"><ac:parameter ac:name="">Saltzer 75</ac:parameter></ac:structured-macro>
[Saltzer 75] Saltzer, J. H., & Schroeder, M. D. "The Protection of Information in Computer Systems." Proceedings of the IEEE 63, 9 (September 1975): 1278-1308.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="07499519-ed79-4cdd-affa-93f7cdc01616"><ac:parameter ac:name="">Saks 99</ac:parameter></ac:structured-macro>
[Saks 99] Saks, Dan. "const T vs.T const." Embedded Systems Programming, February 1999, pp. 13-16.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="45968018-cd0a-42c8-9ad0-d51ab00f05d3"><ac:parameter ac:name="">Saks 00</ac:parameter></ac:structured-macro>
[Saks 00] Saks, Dan. "Numeric Literals." Embedded Systems Programming, September 2000.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="e1eeb600-3a48-460c-b14c-21a1449f1cd1"><ac:parameter ac:name="">Saks 01a</ac:parameter></ac:structured-macro>
[Saks 01a] Saks, Dan. "Symbolic Constants." Embedded Systems Design, November 2001.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="2d5ca548-892e-47bc-a52d-8c3eefb2397b"><ac:parameter ac:name="">Saks 01b</ac:parameter></ac:structured-macro>
[Saks 01b] Saks, Dan. "Enumeration Constants vs. Constant Objects." Embedded Systems Design, November 2001.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="ca6dffcb-caea-44af-acfe-8e3c38c600d7"><ac:parameter ac:name="">Saks 02</ac:parameter></ac:structured-macro>
[Saks 02] Saks, Dan. "Symbolic Constant Expressions." Embedded Systems Design, February 2002.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="f6eef081-96c0-48fa-80a8-d422ae261ca1"><ac:parameter ac:name="">Saks 05</ac:parameter></ac:structured-macro>
[Saks 05] Saks, Dan. "Catching Errors Early with Compile-Time Assertions." Embedded Systems Design, June 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="2a9690c9-4814-4c8f-93a2-147a664bc06c"><ac:parameter ac:name="">Saks 07a</ac:parameter></ac:structured-macro>
[Saks 07a] Saks, Dan. "Sequence Points" Embedded Systems Design, July 1, 2002.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="222eba44-8419-48fd-a9d2-28e25d4d1596"><ac:parameter ac:name="">Saks 07b</ac:parameter></ac:structured-macro>
[Saks 07b] Saks, Dan. Bail, return, jump, or . . . throw?. Embedded Systems Design, March 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="636ee494-5365-428b-8253-845bb843a19a"><ac:parameter ac:name="">Saks 08</ac:parameter></ac:structured-macro>
[Saks 08] Saks, Dan, & Dewhurst, Stephen C. "Sooner Rather Than Later: Static Programming Techniques for C++" (presentation, March 2008).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="4eeb6b27-c9e6-4915-b10d-135783867926"><ac:parameter ac:name="">Schwarz 05</ac:parameter></ac:structured-macro>
[Schwarz 05] Schwarz, B., Wagner, Hao Chen, Morrison, D., West, G., Lin, J., & Tu, J. Wei. "Model checking an entire Linux distribution for security violations." Proceedings of the 21st Annual Computer Security Applications Conference, December 2005 (ISSN 1063-9527; ISBN 0-7695-2461-3).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="4235603d-141d-44dc-89f3-4382050e1be0"><ac:parameter ac:name="">Seacord 03</ac:parameter></ac:structured-macro>
[Seacord 03] Seacord, Robert C., Plakosh, Daniel, & Lewis, Grace A. Modernizing Legacy Systems: Software Technologies, Engineering Processes, and Business Practices. Addison-Wesley, February 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="a5702ab5-1f08-47d7-80eb-03b8c25ce265"><ac:parameter ac:name="">Seacord 05</ac:parameter></ac:structured-macro> <ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="f700e5fc-9b05-449f-99cf-c03c7b81f9b3"><ac:parameter ac:name="">Seacord 05a</ac:parameter></ac:structured-macro>
[Seacord 05a] Seacord, Robert C. Secure Coding in C and C++. Boston, MA: Addison-Wesley, 2005. See http://www.cert.org/books/secure-coding for news and errata.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="9361568e-1341-4f2d-a6f7-28cf3c2c1427"><ac:parameter ac:name="">Seacord 05b</ac:parameter></ac:structured-macro>
[Seacord 05b] Seacord, Robert C. "Managed String Library for C, C/C++." Users Journal 23, 10 (October 2005): 30---34.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="2d5b3b81-d0df-41d6-be68-e153080ac3a2"><ac:parameter ac:name="">Seacord 05c</ac:parameter></ac:structured-macro>
[Seacord 05c] Seacord, Robert C. Variadic Functions: How they contribute to security vulnerabilities and how to fix them. Linux World Magazine, November 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="01469c1f-b88d-4f73-bb58-3dd012fc33e6"><ac:parameter ac:name="">Secunia</ac:parameter></ac:structured-macro>
[Secunia] Secunia Advisory SA10635, "HP-UX calloc Buffer Size Miscalculation Vulnerability," 2004.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="97936fc2-b7fe-4c3f-b72d-4f163c19ade2"><ac:parameter ac:name="">SecurityFocus 07</ac:parameter></ac:structured-macro>
[SecurityFocus 07] SecurityFocus. "Linux Kernel Floating Point Exception Handler Local Denial of Service Vulnerability," 2001.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="eaee0460-72e9-47f7-9706-4396eb6062ad"><ac:parameter ac:name="">SecuriTeam 07</ac:parameter></ac:structured-macro>
[SecuriTeam 07] SecuriTeam. "Microsoft Visual C++ 8.0 Standard Library Time Functions Invalid Assertion DoS (Problem 3000)," February 13, 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="a6d1b72c-eeec-42af-bb31-b323272915cb"><ac:parameter ac:name="">Sloss 04</ac:parameter></ac:structured-macro>
[Sloss 04] Sloss, Andrew, Symes, Dominic, & Wright, Chris. ARM System Developer's Guide. San Francisco:Elsevier/Morgan Kauffman, 2004 (ISBN-10: 1558608745; ISBN-13: 978-1558608740).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="a0b68d06-2984-4338-bc95-a9e749149613"><ac:parameter ac:name="">Spinellis 06</ac:parameter></ac:structured-macro>
[Spinellis 06] Spinellis, Diomidis. Code Quality: The Open Source Perspective. Addison-Wesley, 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="b601f558-bf60-438f-996c-b83d35bed72b"><ac:parameter ac:name="">Steele 77</ac:parameter></ac:structured-macro>
[Steele 77] Steele, G. L. "Arithmetic shifting considered harmful." SIGPLAN Not. 12, 11 (November 1977), 61-69.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="8eea45b9-359d-474c-9b46-bb4be5314282"><ac:parameter ac:name="">Summit 95</ac:parameter></ac:structured-macro>
[Summit 95] Summit, Steve. C Programming FAQs: Frequently Asked Questions. Boston, MA: Addison-Wesley, 1995 (ISBN 0201845199).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="a7bb4b80-af37-4a2a-80b6-4f48d8d99011"><ac:parameter ac:name="">Summit 05</ac:parameter></ac:structured-macro>
[Summit 05] Summit, Steve. comp.lang.c Frequently Asked Questions, 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="55af1e14-7d61-47c0-ab14-38c2e288593f"><ac:parameter ac:name="">Sun</ac:parameter></ac:structured-macro>
[Sun] Sun Security Bulletin #00122, 1993.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="7157c1c6-60dd-400a-b7ac-446335308a7b"><ac:parameter ac:name="">Sun 05</ac:parameter></ac:structured-macro>
[Sun 05] C User's Guide. 819-3688-10. Sun Microsystems, Inc., 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="fba65198-8bf1-458b-90b6-0a1875d45b49"><ac:parameter ac:name="">Sutter 04</ac:parameter></ac:structured-macro>
[Sutter 04] Sutter, Herb & Alexandrescu, Andrei. C++ Coding Standards: 101 Rules, Guidelines, and Best Practices. Boston, MA:Addison-Wesley Professional, 2004 (ISBN 0321113586).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="9e6877f0-950d-47e5-a13f-1003bf2e550a"><ac:parameter ac:name="">Tsafrir 08</ac:parameter></ac:structured-macro>
[Tsafrir 08] Tsafrir, Dan, Da Silva, Dilma, & Wagner, David. The Murky Issue of Changing Process Identity: Revising "Setuid Demystified" USENIX, June 2008, pages 55-66
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="74c158c5-4083-4448-9eaa-f94c0d73e470"><ac:parameter ac:name="">Unicode 06</ac:parameter></ac:structured-macro>
[Unicode 06] The Unicode Consortium. The Unicode Standard, Version 5.0. Addison-Wesley Professional; 5th edition (November 3, 2006) ISBN: 0321480910.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="6906e3ee-89b3-462c-8a80-858896c057a3"><ac:parameter ac:name="">van de Voort 07</ac:parameter></ac:structured-macro>
[van de Voort 07] van de Voort, Marco. Development Tutorial (a.k.a Build FAQ), January 29, 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="37439a2c-0c91-4af8-aa30-37dd0277805f"><ac:parameter ac:name="">van Sprundel06</ac:parameter></ac:structured-macro>
[van Sprundel 06] van Sprundel, Ilja. Unusualbugs, 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="b75a90c1-80b8-499e-a937-d2398529ccaf"><ac:parameter ac:name="">Viega 01</ac:parameter></ac:structured-macro>
[Viega 01] Viega, John. Protecting Sensitive Data in Memory, February 2001.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="10020b32-8aec-440c-9844-357624a2d249"><ac:parameter ac:name="">Viega 03</ac:parameter></ac:structured-macro>
[Viega 03] Viega, John, & Messier, Matt. Secure Programming Cookbook for C and C++: Recipes for Cryptography, Authentication, Networking, Input Validation & More. Sebastopol, CA: O'Reilly, 2003 (ISBN 0-596-00394-3).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="7dc029bf-547c-4baa-80fd-43be26bbcf93"><ac:parameter ac:name="">Viega 05</ac:parameter></ac:structured-macro>
[Viega 05] Viega, John. CLASP Reference Guide Volume 1.1. Secure Software, 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="b91745dc-4d14-43da-a58c-b4be21cdda41"><ac:parameter ac:name="">VU#159523</ac:parameter></ac:structured-macro>
[VU#159523] Giobbi, Ryan. Vulnerability Note VU#159523, Adobe Flash Player integer overflow vulnerability, April 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="94de310f-954c-4d43-a158-163238a7804f"><ac:parameter ac:name="">VU#162289</ac:parameter></ac:structured-macro>
[VU#162289] Dougherty, Chad. Vulnerability Note VU#162289, gcc silently discards some wraparound checks, April 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="8fb73736-9017-47fa-8880-f21b0c49d198"><ac:parameter ac:name="">VU196240</ac:parameter></ac:structured-macro>
[VU#196240] Taschner, Chris & Manion, Art. Vulnerability Note VU#196240, Sourcefire Snort DCE/RPC preprocessor does not properly reassemble fragmented packets, 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="1e8f3e34-a9ef-4ca3-bdd9-fe5b60ffeaae"><ac:parameter ac:name="">VU286468</ac:parameter></ac:structured-macro>
[VU#286468] Burch, Hal. Vulnerability Note VU#286468, Ettercap contains a format string error in the "curses_msg()" function, 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="7fbc024e-e0ef-4ece-8a0d-dbe4d7ecefe9"><ac:parameter ac:name="">VU439395</ac:parameter></ac:structured-macro>
[VU#439395] Lipson, Howard. Vulnerability Note VU#439395, Apache web server performs case sensitive filtering on Mac OS X HFS+ case insensitive filesystem, 2001.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="ab73c083-79d5-49b4-acdb-c004d0d0bb9e"><ac:parameter ac:name="">VU551436</ac:parameter></ac:structured-macro>
[VU#551436] Giobbi, Ryan. Vulnerability Note VU#551436, Mozilla Firefox SVG viewer vulnerable to buffer overflow, 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="89d03f34-9146-490b-a7ab-026416306fd4"><ac:parameter ac:name="">VU568148</ac:parameter></ac:structured-macro>
[VU#568148] Finlay, Ian A. & Morda, Damon G. Vulnerability Note VU#568148, Microsoft Windows RPC vulnerable to buffer overflow, 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="1ba0f484-968a-4090-8eee-7e67829a4d1f"><ac:parameter ac:name="">VU623332</ac:parameter></ac:structured-macro>
[VU#623332] Mead, Robert. Vulnerability Note VU#623332, MIT Kerberos 5 contains double free vulnerability in "krb5_recvauth()" function, 2005.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="75de7a41-0dec-4b2f-88f0-b683608dc862"><ac:parameter ac:name="">VU649732</ac:parameter></ac:structured-macro>
[VU#649732] Gennari, Jeff. Vulnerability Note VU#649732, Samba AFS ACL Mapping VFS Plug-In Format String Vulnerability, 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="5d2de916-a032-48f7-99d2-264fce78d9c3"><ac:parameter ac:name="">VU654390</ac:parameter></ac:structured-macro>
[VU#654390] Rafail, Jason A. Vulnerability Note VU#654390, ISC DHCP contains C Includes that define vsnprintf() to vsprintf() creating potential buffer overflow conditions, June 2004.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="a594a560-5538-4b13-a8be-39f4a14b6ecb"><ac:parameter ac:name="">VU743092</ac:parameter></ac:structured-macro>
[VU#743092] Rafail, Jason A. & Havrilla, Jeffrey S. Vulnerability Note VU#743092, realpath(3) function contains off-by-one buffer overflow, July 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="f45c4c4a-3d2b-47ff-b96a-221f490c75c8"><ac:parameter ac:name="">VU834865</ac:parameter></ac:structured-macro>
[VU#834865] Gennari, Jeff. Vulnerability Note VU#834865, Sendmail signal I/O race condition, March 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="02f87e52-d7d8-493a-a787-1674b94c3688"><ac:parameter ac:name="">VU837857</ac:parameter></ac:structured-macro>
[VU#837857] Dougherty, Chad. Vulnerability Note VU#837857, SX.Org server fails to properly test for effective user ID, August 2006.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="4021ea80-03f0-4542-abb3-2b7c711624a1"><ac:parameter ac:name="">VU881872</ac:parameter></ac:structured-macro>
[VU#881872] Manion, Art & Taschner, Chris. Vulnerability Note VU#881872, Sun Solaris telnet authentication bypass vulnerability, 2007.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="2318b725-cd65-4029-998e-0f4b4f10b13b"><ac:parameter ac:name="">Warren 02</ac:parameter></ac:structured-macro>
[Warren 02] Warren, Henry S. Hacker's Delight. Boston, MA: Addison Wesley Professional, 2002 (ISBN 0201914654).
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="5a79c43b-2204-4a5b-9ced-d3c4517c14d7"><ac:parameter ac:name="">Wheeler 03</ac:parameter></ac:structured-macro>
[Wheeler 03] Wheeler, David. Secure Programming for Linux and Unix HOWTO, v3.010, March 2003.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="844ad6a9-7b8e-4f8d-bb57-3d9199689562"><ac:parameter ac:name="">Wheeler 04</ac:parameter></ac:structured-macro>
[Wheeler 04] Wheeler, David. Secure programmer: Call components safely. December 2004.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="faa6b321-3324-4b49-a716-90b367624d8a"><ac:parameter ac:name="">Wojtczuk 08</ac:parameter></ac:structured-macro>
[Wojtczuk 08] Wojtczuk, Rafal. "Analyzing the Linux Kernel vmsplice Exploit." McAfee Avert Labs Blog, February 13, 2008.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="5bf7960e-7346-475e-a3d4-87e1c5f2030a"><ac:parameter ac:name=""> xorl 2009</ac:parameter></ac:structured-macro>
[xorl 2009] xorl. xorl %eax, %eax.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="b56bbb01-8183-46c1-83ae-16f25359654d"><ac:parameter ac:name="">Yergeau 98</ac:parameter></ac:structured-macro>
[Yergeau 98] Yergeau, F. RFC 2279 - UTF-8, a transformation format of ISO 10646, January 1998.
<ac:structured-macro ac:name="anchor" ac:schema-version="1" ac:macro-id="2104f6f2-ac5a-44da-a9a2-fe269646b3ce"><ac:parameter ac:name="">Zalewski 01</ac:parameter></ac:structured-macro>
[Zalewski 01] Zalewski, Michal. Delivering Signals for Fun and Profit: Understanding, exploiting and preventing signal-handling related vulnerabilities, May 2001.