[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CWE
view XML

Truncation of Security-relevant Information

ID: 222Date: (C)2012-05-14   (M)2022-10-10
Type: weaknessStatus: DRAFT
Abstraction Type: Base





Description

The application truncates the display, recording, or processing of security-relevant information in a way that can obscure the source or nature of an attack.

Applicable Platforms
Language Class: All

Time Of Introduction

  • Architecture and Design
  • Implementation
  • Operation

Common Consequences

ScopeTechnical ImpactNotes
Non-Repudiation
 
Hide activities
 
The source of an attack will be difficult or impossible to determine. This can allow attacks to the system to continue without notice.
 

Detection Methods
None

Potential Mitigations
None

Relationships

Related CWETypeViewChain
CWE-222 ChildOf CWE-906 Category CWE-888  

Demonstrative Examples
None

Observed Examples

  1. CVE-2005-0585 : Web browser truncates long sub-domains or paths, facilitating phishing.
  2. CVE-2004-2032 : Bypass URL filter via a long URL with a large number of trailing hex-encoded space characters.
  3. CVE-2003-0412 : Does not log complete URI of a long request (truncation).

For more examples, refer to CVE relations in the bottom box.

White Box Definitions
None

Black Box Definitions
None

Taxynomy Mappings

TaxynomyIdNameFit
PLOVER  Truncation of Security-relevant Information
 
 

References:
None

© SecPod Technologies