结构: Simple
Abstraction: Base
状态: Draft
被利用可能性: unkown
The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service because of excessive looping.
cwe_Nature: ChildOf cwe_CWE_ID: 20 cwe_View_ID: 1000 cwe_Ordinal: Primary
cwe_Nature: ChildOf cwe_CWE_ID: 20 cwe_View_ID: 699 cwe_Ordinal: Primary
cwe_Nature: CanPrecede cwe_CWE_ID: 834 cwe_View_ID: 1000
范围 | 影响 | 注释 |
---|---|---|
Availability | DoS: Resource Consumption (CPU) |
策略:
Do not use user-controlled data for loop conditions.
策略:
Perform input validation.
The following example demonstrates the weakness.
bad C
映射的分类名 | ImNode ID | Fit | Mapped Node Name |
---|---|---|---|
Software Fault Patterns | SFP25 | Tainted input to variable | |
OMG ASCSM | ASCSM-CWE-606 |