CWE-432: Dangerous Signal Handler not Disabled During Sensitive Operations
Dangerous Signal Handler not Disabled During Sensitive Operations
Weakness ID: 432 (Weakness Base)
Status: Draft
Description
Description Summary
The application uses a signal handler that shares state with other signal handlers, but it does not properly mask or prevent those signal handlers from being invoked while the original signal handler is still running.
Extended Description
During the execution of a signal handler, it can be interrupted by another handler when a different signal is sent. If the two handlers share state - such as global variables - then an attacker can corrupt the state by sending another signal before the first handler has completed execution.
Time of Introduction
Architecture and Design
Implementation
Applicable Platforms
Languages
Language-independent
Common Consequences
Scope
Effect
Integrity
Technical Impact: Modify application
data
Potential Mitigations
Phase: Implementation
Turn off dangerous handlers when performing sensitive
operations.