|
|
|
|
CWE-528: Information Leak Through Core Dump Files | |
| | Information Leak Through Core Dump Files |
|
| Weakness ID: 528 (Weakness Variant) | | Status: Draft |
Description
Description Summary The application generates a core dump file in a directory that
is accessible to parties outside of the intended control
sphere.
Time of Introduction Potential Mitigations | Phase | Description |
| Protect the core dump files from unauthorized access. |
Relationships Taxonomy Mappings | Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
| Anonymous Tool Vendor (under NDA) | | | |
| CERT C Secure Coding | MEM06-C | | Ensure that sensitive data is not written out to
disk |
Content History | Submissions |
|---|
| Submission Date | Submitter | Organization | Source |
|---|
| Anonymous Tool Vendor (under NDA) | | Externally Mined | | | Modifications |
|---|
| Modification Date | Modifier | Organization | Source |
|---|
| 2008-07-01 | Eric Dalci | Cigital | External | | updated Potential Mitigations,
Time of Introduction | | 2008-09-08 | CWE Content Team | MITRE | Internal | | updated Relationships,
Taxonomy Mappings | | 2008-11-24 | CWE Content Team | MITRE | Internal | | updated Relationships,
Taxonomy Mappings | | 2009-03-10 | CWE Content Team | MITRE | Internal | | updated Relationships |
|