Description
When a user-controlled value selects the destination pointer of a memory write, an attacker can overwrite an unintended address.
Potential impact
- Memory corruption, privilege escalation, denial of service or code execution may follow.
Remediation
Do not use externally selected addresses as write pointers. Choose an application-owned object or buffer as the destination, and ensure the write fits within its bounds.
Examples
Before
Assume the caller can directly choose the destination pointer in request->destination.
c
int *where = request->destination;
*where = 1;
After
c
int value = 0;
int *where = &value;
*where = 1;
The first excerpt dereferences the requested destination without validation. The second restricts the destination to a local variable owned by the function.