Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The result of the / operator is the quotient from the division of the first arithmetic operand by the second arithmetic operand. Division operations are susceptible to divide-by-zero errors. Overflow can also occur during two's-complement signed integer division when the dividend is equal to the minimum (negative) value for the signed integer type and the divisor is equal to —1. ( See rule " NUM00-J . Detect or prevent integer overflow".)for more information. This noncompliant code example can result in a divide-by-zero error during the division of the signed operands num1 and num2.

This code can result in a divide-by-zero error during the division of the signed operands num1 and num2.

...

This compliant solution tests the suspect division operation divisor to guarantee there is no possibility of divide-by-zero errors.

Code Block
bgColor#ccccff
long num1, num2, result;

/* Initialize num1 and num2 */

if ((num2 == 0)) {
  // handle error
} else {
  result = num1 / num2;
}

...

The % operator provides the remainder when two operands of integer type are divided. This noncompliant code example can result in a divide-by-zero error during the remainder operation on the signed operands num1 and num2.

Code Block
bgColor#FFcccc
long num1, num2, result;

/* Initialize num1 and num2 */

result = num1 % num2;

Compliant Solution (Modulo)

This compliant solution tests the suspect remainder operation divisor to guarantee there is no possibility of a divide-by-zero error.

Code Block
bgColor#ccccff
long num1, num2, result;

/* Initialize num1 and num2 */

if ((num2 == 0)) {
  // handle error
} else {
  result = num1 % num2;
}

Risk Assessment

A divide-division or modulo by - zero can result in abnormal program termination and denial of service (DoS).

Rule

Severity

Likelihood

Remediation Cost

Priority

Level

NUM02-J

low

likely

medium

P6

L2

...

Automated detection exists for C and C++ , but not for Java yet.

Related Guidelines

Bibliography

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="6c81027a0d5d1f31-aaf8a21d-49974ea2-8d1ba938-90f951ee43f1d62a3dc94f4a"><ac:plain-text-body><![CDATA[

[[ISO/IEC 9899:1999

AA. Bibliography#ISO/IEC 9899-1999]]

Section 6.5.5, " Multiplicative operators"Operators

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="7c72543baccd5296-b61a1948-404b4f90-a5dcb431-dfa10c08b05f94d470ee281a"><ac:plain-text-body><![CDATA[

[[Seacord 05

AA. Bibliography#Seacord 05]]

Chapter 5, " Integers"

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="68b168d3f8b39cc3-cd12344b-47754700-9889b6de-cbe499ac7707df99e9ad7bb9"><ac:plain-text-body><![CDATA[

[[Warren 02

AA. Bibliography#Warren 02]]

Chapter 2, " Basics"

]]></ac:plain-text-body></ac:structured-macro>

...