Description
The product does not check for an error after calling a function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference.
Potential Impact
- Availability: DoS: Crash, Exit, or Restart
- Integrity: Execute Unauthorized Code or Commands
Detection Methods
- Black Box: This typically occurs in rarely-triggered error conditions, reducing the chances of detection during black box testing....
- White Box: Code analysis can require knowledge of API behaviors for library functions that might return NULL, reducing the chances of detection when unknown libraries are used....
- Automated Dynamic Analysis: Use tools that are integrated during
compilation to insert runtime error-checking mechanisms
related to memory safety errors, such as AddressSanitizer
(ASan) for C/C++ [REF-1518]....
Related Weaknesses
References
View on MITRE CWE Database →