/* goodG2B() - use goodsource and badsink */ public static void GoodG2BSink(CWE190_Integer_Overflow__Short_console_readLine_square_67a.Container dataContainer) { short data = dataContainer.containerOne; /* POTENTIAL FLAW: if (data*data) > short.MaxValue, this will overflow */ short result = (short)(data * data); IO.WriteLine("result: " + result); }
/* goodB2G() - use badsource and goodsink */ public static void GoodB2GSink(CWE190_Integer_Overflow__Short_console_readLine_square_67a.Container dataContainer) { short data = dataContainer.containerOne; /* FIX: Add a check to prevent an overflow from occurring */ if (Math.Abs((long)data) <= (long)Math.Sqrt(short.MaxValue)) { short result = (short)(data * data); IO.WriteLine("result: " + result); } else { IO.WriteLine("data value is too large to perform squaring."); } }