/* goodG2B() - use goodsource and badsink */ private static void GoodG2B() { ulong data = CWE190_Integer_Overflow__UInt64_rand_square_61b.GoodG2BSource(); /* POTENTIAL FLAW: if (data*data) > ulong.MaxValue, this will overflow */ ulong result = (ulong)(data * data); IO.WriteLine("result: " + result); }
public override void Bad() { ulong data = CWE190_Integer_Overflow__UInt64_rand_square_61b.BadSource(); /* POTENTIAL FLAW: if (data*data) > ulong.MaxValue, this will overflow */ ulong result = (ulong)(data * data); IO.WriteLine("result: " + result); }
/* goodB2G() - use badsource and goodsink */ private static void GoodB2G() { ulong data = CWE190_Integer_Overflow__UInt64_rand_square_61b.GoodB2GSource(); /* FIX: Add a check to prevent an overflow from occurring */ if (Math.Abs((long)data) <= (long)Math.Sqrt(ulong.MaxValue)) { ulong result = (ulong)(data * data); IO.WriteLine("result: " + result); } else { IO.WriteLine("data value is too large to perform squaring."); } }