Cigital ITS4 Software Security Tool...

- AV AC AU C I A
发布: 2002-02-18
修订: 2025-04-13

Cigital's ITS4 tool is designed to automatically scan C and C++ source code, and will attempt to flag potentially dangerous function calls. It is based on a relatively simple parsing system, and scans against a database of known dangerous functions, such as strcpy and sprintf. The documentation for ITS4 states that some attempt is made to perform more detailed analysis of code. This is implemented through custom handlers defined for certain functions. For example, if sprintf() is called with a fixed format string, it may be assumed that it is not vulnerable to a standard format string attack. The design of ITS4 allows several forms of vulnerable code to pass undetected. Several examples of this have been published. Many are based upon the assumption that constant values are safe. For example, a call to strcpy() or sprintf() with a statically defined string is assumed to be safe, as is the length passed to a call to strncpy(). Additional cases not covered by ITS4 are clearly...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息