CAPEC 24 Filter Failure through Buffer Overflow

Draft Detailed High Risk
Severity High

Description

In this attack, the idea is to cause an active filter to fail by causing an oversized transaction. An attacker may try to feed overly long input strings to the program in an attempt to overwhelm the filter (by causing a buffer overflow) and hoping that the filter does not fail securely (i.e. the user input is let into the system unfiltered).

Attack Execution Flow

4

Mitigations

5

Consequences

Indicators

1

Relationships