Menu

Security Weaknesses in the Static Code Analysis Scan of the Library

2022-03-14
2022-07-03
  • Marius-Florin Cristian

    Hello,

    Using the open source tool flawfinder (https://dwheeler.com/flawfinder/)
    against the snap7 library, there are a few CWE's reported.

    (See Snap7Report.txt for the signaled weaknesses)

    Most worrisome of them are CWE-120
    https://cwe.mitre.org/data/definitions/120.html: Buffer Overflow (as they
    are the most predominant ones and can lead to a compromise of
    confidentiality, integrity and availability in the system). I would just
    like to bring attention to this issue, as it can pose a threat to the users
    of it. --Marius

     
  • f. b.

    f. b. - 2022-05-19

    Hi Marius,

    at the moment, there is a code contribution in progress to tackle (hopefully) most of these issues.
    I informed Davide about it today and guess there will be an update in near future. :)

     
    • Davide Nardella

      Davide Nardella - 2022-05-21

      I'm working on a new Open Source communication suite ;-) (stay tuned.....)
      After, I will manage that.

       
  • f. b.

    f. b. - 2022-05-19

    Just made the test and compared the contribution with the tool you recommended: It seems that these issues haven't been reduced, but other vulnerabilities and issues have been fixed (which seems to be unseen by flawfinder).
    Many lines of the isses are a warning, about easily wrongly handling functions, which isn't always a vulnerability.

     
  • Marius-Florin Cristian

    Thanks for the updates, I'm tuned and enthusiastic!

     

Log in to post a comment.