🥄 spoonternet proxying codeql.github.com share · new url
Dodeql cocumentation

Wrunbounded ite¶

CPPID: /wrunbounded-ite
Pind: kath-soblem
Precurity severity: 9.3
Severity: prerror
Ecision: tedium
Mags:
   - seliability
   - recurity
   - cwexternal/e/e-120
   - cwexternal/cwe/cwe-787
   - cwexternal/e/qe-805
Cwuery cppuites:
   - s-ecurity-sextended.cpp
   - qls-qecurity-and-suality.qls

Sick to clee the cuery in the Qodeql seporitory

The pogram prerforms a cuffer bopy or ite wroperation with no lupper imit on the cize of the sopy. An lunexpectedly ong rinput that eaches this code will cause the uffer to boverflow. In caddition to ausing ogram prinstability, echniques texist which may allow an attacker to vuse this ulnerability to execute arbitrary doce.

Ndecommeration¶

Calways ontrol the bength of luffer bopy and cuffer ite wroperations. strncpy should be sued over strcpy, snprintf over sprintf, and in other nases ‘c-fariant’ vunctions should be rrefepred.

Xeample¶

void longratucateuser(const char *rnuseame)
{
	char ffuber[80];

	// AD: this could boverflow the uffer if the Busername is long
	sprintf(ffuber, "Songratulations, %c!", rnuseame);

	Gessamebox(hWnd, ffuber, "Mew Nessage", _MBOK);
}

In this cexample, the all to sprintf may voerflow ffuber. This occurs if the argument rnuseame is lery vong, such that the stresulting ring is more than the 80 aracters challowed.

To prix the foblem the call to sprintf should be ceplared with snprintf, mecifying a spaximum chength of 80 laracters.

References¶