CWE-130

Overview
  • CWE ID
  • 130
  • CWE Name
  • Improper Handling of Length Parameter Inconsistency
  • CWE Abstraction
  • Base
  • CWE structure
  • Simple
  • CWE Status
  • Incomplete
Description
The software parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
Extended Description
If an attacker can manipulate the length parameter associated with an input such that it is inconsistent with the actual length of the input, this can be leveraged to cause the target application to behave in unexpected, and possibly, malicious ways. One
Related CWEs
CWE ID View ID Nature Ordinal
240 1000 ChildOf Primary
119 1305 ChildOf Primary
119 1340 ChildOf Primary
805 1000 CanPrecede