...
Rule | Severity | Likelihood | Detectable | Repairable | Priority | Level |
|---|---|---|---|---|---|---|
FIO05-J | Medium | Likely | No | No | P6 | L2 |
Automated Detection
Sound automated detection of this vulnerability is not feasible. Heuristic approaches may be useful.
| Tool | Version | Checker | Description | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Parasoft Jtest |
| CERT.FIO05.BUFEXP | Do not expose data wrapped by a buffer to untrusted code | ||||||
| Security Reviewer - Static Reviewer |
| Idor04 | Full Implementation | ||||||
| SpotBugs |
| MS_EXPOSE_BUF | Implemented (since 4.3.0) |
Bibliography
[API 2014] | |
Section 2.3 "Duplicating Buffers" |
...