CWE-432: Dangerous Handler not Disabled During Sensitive Operations
Dangerous Handler not Disabled During Sensitive Operations
Weakness ID: 432 (Weakness Base)
Status: Draft
Description
Description Summary
The application does not properly clear or disable dangerous
handlers during sensitive operations.
Extended Description
Not disabling a dangerous handler might allow an attacker to invoke the
handler at unexpected times. This can cause the software to enter an invalid
state.
Time of Introduction
Architecture and Design
Implementation
Applicable Platforms
Languages
All
Potential Mitigations
Phase
Description
Turn off dangerous handlers when performing sensitive
operations.