|
1 | 1 | edges
|
2 |
| -| field_conflation.c:12:22:12:27 | call to getenv | field_conflation.c:13:3:13:18 | Chi | |
3 |
| -| field_conflation.c:12:22:12:34 | (const char *)... | field_conflation.c:13:3:13:18 | Chi | |
4 |
| -| field_conflation.c:13:3:13:18 | Chi | field_conflation.c:19:15:19:17 | taint_array output argument | |
5 |
| -| field_conflation.c:19:15:19:17 | taint_array output argument | field_conflation.c:20:10:20:13 | (unsigned long)... | |
6 |
| -| field_conflation.c:19:15:19:17 | taint_array output argument | field_conflation.c:20:13:20:13 | x | |
7 |
| -| field_conflation.c:19:15:19:17 | taint_array output argument | field_conflation.c:20:13:20:13 | x | |
8 |
| -| field_conflation.c:19:15:19:17 | taint_array output argument | field_conflation.c:20:13:20:13 | x | |
9 |
| -| field_conflation.c:20:13:20:13 | x | field_conflation.c:20:10:20:13 | (unsigned long)... | |
10 |
| -| field_conflation.c:20:13:20:13 | x | field_conflation.c:20:13:20:13 | x | |
11 | 2 | | test.cpp:39:21:39:24 | argv | test.cpp:42:38:42:44 | (size_t)... |
|
12 | 3 | | test.cpp:39:21:39:24 | argv | test.cpp:42:38:42:44 | (size_t)... |
|
13 | 4 | | test.cpp:39:21:39:24 | argv | test.cpp:42:38:42:44 | tainted |
|
|
69 | 60 | | test.cpp:235:11:235:20 | (size_t)... | test.cpp:214:23:214:23 | s |
|
70 | 61 | | test.cpp:237:10:237:19 | (size_t)... | test.cpp:220:21:220:21 | s |
|
71 | 62 | nodes
|
72 |
| -| field_conflation.c:12:22:12:27 | call to getenv | semmle.label | call to getenv | |
73 |
| -| field_conflation.c:12:22:12:34 | (const char *)... | semmle.label | (const char *)... | |
74 |
| -| field_conflation.c:13:3:13:18 | Chi | semmle.label | Chi | |
75 |
| -| field_conflation.c:19:15:19:17 | taint_array output argument | semmle.label | taint_array output argument | |
76 |
| -| field_conflation.c:20:10:20:13 | (unsigned long)... | semmle.label | (unsigned long)... | |
77 |
| -| field_conflation.c:20:10:20:13 | (unsigned long)... | semmle.label | (unsigned long)... | |
78 |
| -| field_conflation.c:20:13:20:13 | x | semmle.label | x | |
79 |
| -| field_conflation.c:20:13:20:13 | x | semmle.label | x | |
80 |
| -| field_conflation.c:20:13:20:13 | x | semmle.label | x | |
81 | 63 | | test.cpp:39:21:39:24 | argv | semmle.label | argv |
|
82 | 64 | | test.cpp:39:21:39:24 | argv | semmle.label | argv |
|
83 | 65 | | test.cpp:42:38:42:44 | (size_t)... | semmle.label | (size_t)... |
|
@@ -141,7 +123,6 @@ nodes
|
141 | 123 | | test.cpp:235:11:235:20 | (size_t)... | semmle.label | (size_t)... |
|
142 | 124 | | test.cpp:237:10:237:19 | (size_t)... | semmle.label | (size_t)... |
|
143 | 125 | #select
|
144 |
| -| field_conflation.c:20:3:20:8 | call to malloc | field_conflation.c:12:22:12:27 | call to getenv | field_conflation.c:20:13:20:13 | x | This allocation size is derived from $@ and might overflow | field_conflation.c:12:22:12:27 | call to getenv | user input (getenv) | |
145 | 126 | | test.cpp:42:31:42:36 | call to malloc | test.cpp:39:21:39:24 | argv | test.cpp:42:38:42:44 | tainted | This allocation size is derived from $@ and might overflow | test.cpp:39:21:39:24 | argv | user input (argv) |
|
146 | 127 | | test.cpp:43:31:43:36 | call to malloc | test.cpp:39:21:39:24 | argv | test.cpp:43:38:43:63 | ... * ... | This allocation size is derived from $@ and might overflow | test.cpp:39:21:39:24 | argv | user input (argv) |
|
147 | 128 | | test.cpp:45:31:45:36 | call to malloc | test.cpp:39:21:39:24 | argv | test.cpp:45:38:45:63 | ... + ... | This allocation size is derived from $@ and might overflow | test.cpp:39:21:39:24 | argv | user input (argv) |
|
|
0 commit comments