|
1 | 1 | edges |
2 | | -| field_conflation.c:12:22:12:27 | call to getenv | field_conflation.c:13:3:13:18 | Chi | |
3 | | -| field_conflation.c:12:22:12:34 | (const char *)... | field_conflation.c:13:3:13:18 | Chi | |
4 | | -| field_conflation.c:13:3:13:18 | Chi | field_conflation.c:19:15:19:17 | taint_array output argument | |
5 | | -| field_conflation.c:19:15:19:17 | taint_array output argument | field_conflation.c:20:10:20:13 | (unsigned long)... | |
6 | | -| field_conflation.c:19:15:19:17 | taint_array output argument | field_conflation.c:20:13:20:13 | x | |
7 | | -| field_conflation.c:19:15:19:17 | taint_array output argument | field_conflation.c:20:13:20:13 | x | |
8 | | -| field_conflation.c:19:15:19:17 | taint_array output argument | field_conflation.c:20:13:20:13 | x | |
9 | | -| field_conflation.c:20:13:20:13 | x | field_conflation.c:20:10:20:13 | (unsigned long)... | |
10 | | -| field_conflation.c:20:13:20:13 | x | field_conflation.c:20:13:20:13 | x | |
11 | 2 | | test.cpp:39:21:39:24 | argv | test.cpp:42:38:42:44 | (size_t)... | |
12 | 3 | | test.cpp:39:21:39:24 | argv | test.cpp:42:38:42:44 | (size_t)... | |
13 | 4 | | test.cpp:39:21:39:24 | argv | test.cpp:42:38:42:44 | tainted | |
|
69 | 60 | | test.cpp:235:11:235:20 | (size_t)... | test.cpp:214:23:214:23 | s | |
70 | 61 | | test.cpp:237:10:237:19 | (size_t)... | test.cpp:220:21:220:21 | s | |
71 | 62 | nodes |
72 | | -| field_conflation.c:12:22:12:27 | call to getenv | semmle.label | call to getenv | |
73 | | -| field_conflation.c:12:22:12:34 | (const char *)... | semmle.label | (const char *)... | |
74 | | -| field_conflation.c:13:3:13:18 | Chi | semmle.label | Chi | |
75 | | -| field_conflation.c:19:15:19:17 | taint_array output argument | semmle.label | taint_array output argument | |
76 | | -| field_conflation.c:20:10:20:13 | (unsigned long)... | semmle.label | (unsigned long)... | |
77 | | -| field_conflation.c:20:10:20:13 | (unsigned long)... | semmle.label | (unsigned long)... | |
78 | | -| field_conflation.c:20:13:20:13 | x | semmle.label | x | |
79 | | -| field_conflation.c:20:13:20:13 | x | semmle.label | x | |
80 | | -| field_conflation.c:20:13:20:13 | x | semmle.label | x | |
81 | 63 | | test.cpp:39:21:39:24 | argv | semmle.label | argv | |
82 | 64 | | test.cpp:39:21:39:24 | argv | semmle.label | argv | |
83 | 65 | | test.cpp:42:38:42:44 | (size_t)... | semmle.label | (size_t)... | |
@@ -141,7 +123,6 @@ nodes |
141 | 123 | | test.cpp:235:11:235:20 | (size_t)... | semmle.label | (size_t)... | |
142 | 124 | | test.cpp:237:10:237:19 | (size_t)... | semmle.label | (size_t)... | |
143 | 125 | #select |
144 | | -| field_conflation.c:20:3:20:8 | call to malloc | field_conflation.c:12:22:12:27 | call to getenv | field_conflation.c:20:13:20:13 | x | This allocation size is derived from $@ and might overflow | field_conflation.c:12:22:12:27 | call to getenv | user input (getenv) | |
145 | 126 | | test.cpp:42:31:42:36 | call to malloc | test.cpp:39:21:39:24 | argv | test.cpp:42:38:42:44 | tainted | This allocation size is derived from $@ and might overflow | test.cpp:39:21:39:24 | argv | user input (argv) | |
146 | 127 | | test.cpp:43:31:43:36 | call to malloc | test.cpp:39:21:39:24 | argv | test.cpp:43:38:43:63 | ... * ... | This allocation size is derived from $@ and might overflow | test.cpp:39:21:39:24 | argv | user input (argv) | |
147 | 128 | | test.cpp:45:31:45:36 | call to malloc | test.cpp:39:21:39:24 | argv | test.cpp:45:38:45:63 | ... + ... | This allocation size is derived from $@ and might overflow | test.cpp:39:21:39:24 | argv | user input (argv) | |
|
0 commit comments