Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Helix QAC

Tool

Version

Checker

Description

Axivion Bauhaus Suite

Include Page
Axivion Bauhaus Suite_V
Axivion Bauhaus Suite_V

CertC-DCL39Detects composite structures with padding, in particular those passed to trust boundary routines.
Helix QAC

Include Page
Helix QAC_V
Helix QAC_V

C: 4941, 4942, 4943

C++: 4941, 4942, 4943


Klocwork
Include Page
Klocwork_V
Klocwork_V
PORTING.STORAGE.STRUCT
PORTING.STRUCT.BOOL

Parasoft C/C++test

Include Page
Parasoft_V
Parasoft_V

CERT_C-DCL39-a

A pointer to a structure should not be passed to a function that can copy data to the user space

Polyspace Bug Finder

Include Page
Polyspace Bug Finder_V
Polyspace Bug Finder_V

CERT C: Rule DCL39-CChecks for information leak via structure padding 
PRQA QA-C

Include Page
PRQA QA-C_v
PRQA QA-C_v

4941, 4942, 4943
PRQA QA-C++
Include Page
cplusplus:PRQA QA-C++_V
cplusplus:PRQA QA-C++_V

4941, 4942, 4943

Helix QAC
Include Page
_V
Helix QAC_V

C: 4941, 4942, 4943

C++: 4941, 4942, 4943


Related Vulnerabilities

Numerous vulnerabilities in the Linux Kernel have resulted from violations of this rule. CVE-2010-4083 describes a vulnerability in which the semctl() system call allows unprivileged users to read uninitialized kernel stack memory because various fields of a semid_ds struct declared on the stack are not altered or zeroed before being copied back to the user.

...