cppcheck News
Static source code analysis tool for C and C++ code
Brought to you by:
danielmarjamaki
I launched a new Kickstarter project today.
https://www.kickstarter.com/projects/3300446/diagnose-buffer-overflow-cve
Thousands of software vulnerabilities are found in released software each year.
I will investigate the reported vulnerabilities and pick a buffer overflow that is not diagnosed by Cppcheck yet. Then I will fix Cppcheck so it detects such overflows.
This is a small step, but in the long run it should be possible to detect most buffer overflows by using Cppcheck.
Perhaps it would be good to add some additional visibility to the Kickstarter by adding something suitably non-obstructive to the introduction part of the Cppcheck homepage (http://cppcheck.sourceforge.net/), if possible. At the moment, the information and link to the Kickstarter is hidden away quite far into the page, only showing up in the news section.
I myself had missed the last Kickstarter (related to MISRA checks) simply by the fact that I did not look that far into the page at the time..
I would agree. I missed the MISRA checks kickstarter as well.