...
Tool | Version | Checker | Description |
|---|---|---|---|
|
|
|
Related Guidelines
| SEI CERT C ++ Secure Coding Standard | VOID ENV00-CPPC. Do not store the pointer to the string returned by objects that can be overwritten by multiple calls to getenv() and similar functions |
| ISO/IEC TR 24731-2 | 5.3.1.1, "The strdup Function" |
| ISO/IEC TS 17961:2013 | Using an object overwritten by getenv, localeconv, setlocale, and strerror [libuse] |
...
| [IEEE Std 1003.1:2013] | Chapter 8, "Environment Variables" XSH, System Interfaces, strdup |
| [ISO/IEC 9899:2011] | Subclause 7.22.4, "Communication with the Environment" Subclause 7.22.4.6, "The getenv Function"Subclause K.3.6.2.1, "The getenv_s Function" |
| [MSDN] | _dupenv_s(), _wdupenv_s() |
| [Viega 2003] | Section 3.6, "Using Environment Variables Securely" |
...