Specifications for Managed Strings

Hal Burch, Fred Long, Robert Seacord

Research output: Book/ReportTechnical Report

Abstract

This report describes a managed string library for the C programming language. Many software vulnerabilities in C programs result from the misuse of standard C string manipulation functions. Programming errors common to string manipulation logic include buffer overflow, truncation errors, string termination errors, and improper data sanitation. The managed string library provides mechanisms to eliminate or mitigate these problems and improve system security. A proof-of-concept implementation of the managed string library is available from the Secure Coding area of the CERT Web site.
Original languageEnglish
Number of pages49
Publication statusPublished - 01 May 2006

Fingerprint

Dive into the research topics of 'Specifications for Managed Strings'. Together they form a unique fingerprint.

Cite this