/* goodG2B() - use goodsource and badsink */ private static void GoodG2B() { byte data; /* FIX: Use a hardcoded number that won't cause underflow, overflow, divide by zero, or loss-of-precision issues */ data = 2; byte[] dataArray = new byte[5]; dataArray[2] = data; CWE190_Integer_Overflow__Byte_rand_add_66b.GoodG2BSink(dataArray); }
/* goodB2G() - use badsource and goodsink */ private static void GoodB2G() { byte data; /* POTENTIAL FLAW: Use a random value */ data = (byte)(new Random().Next(byte.MinValue, byte.MaxValue)); byte[] dataArray = new byte[5]; dataArray[2] = data; CWE190_Integer_Overflow__Byte_rand_add_66b.GoodB2GSink(dataArray); }
public override void Bad() { byte data; /* POTENTIAL FLAW: Use a random value */ data = (byte)(new Random().Next(byte.MinValue, byte.MaxValue)); byte[] dataArray = new byte[5]; dataArray[2] = data; CWE190_Integer_Overflow__Byte_rand_add_66b.BadSink(dataArray); }