Detailedlikelihood: Highseverity: HighDraft
CAPEC-45Buffer Overflow via Symbolic Links
Abstraction
Detailed
Status
Draft
Likelihood
High
Severity
High
Description
This type of attack leverages the use of symbolic links to cause buffer overflows. An adversary can try to create or manipulate a symbolic link file such that its contents result in out of bounds data. When the target software processes the symbolic link file, it could potentially overflow internal buffers with insufficient bounds checking.
Related weaknesses· 9
Related attack patterns· 1
Exploits9
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Incorrect Comparisoncwe-697 | 100% | live |
| Weakness | Authentication Bypass by Assumed-Immutable Datacwe-302 | 100% | live |
| Weakness | Incorrect Access of Indexable Resource ('Range Error')cwe-118 | 100% | live |
| Weakness | Integer Overflow to Buffer Overflowcwe-680 | 100% | live |
| Weakness | Improper Restriction of Operations within the Bounds of a Memory Buffercwe-119 | 100% | live |
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 100% | live |
| Weakness | Improper Authorizationcwe-285 | 100% | live |
| Weakness | Improper Input Validationcwe-20 | 100% | live |
| Weakness | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')cwe-120 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.