Title :
The rising threat of vulnerabilities due to integer errors
Abstract :
Integer errors are mistakes a programmer makes in sensitive operations involving integer data-type variables. Bugs caused by incorrect integer use are a fact of life for developers. In early 2001, it became clear that integer errors frequently cause security vulnerabilities. The article explains the vulnerabilities, and offers guidelines to prevent the introduction of these flaws. The most important thing is to maintain awareness of the risks during software development.
Keywords :
security of data; software engineering; integer data-type variables; integer errors; software vulnerabilities; Arithmetic; Computer errors; Counting circuits; Data privacy; Data security; Detectors; Kernel; Programming profession; World Wide Web;
Journal_Title :
Security & Privacy, IEEE
DOI :
10.1109/MSECP.2003.1219077