Memory String and Unmanaged Code
V1.4.1
Verify that the application uses memory-safe string, safer memory copy and pointer arithmetic to detect or prevent stack, buffer, or heap overflows.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 128, 129, 130, 131, 184, 207, 242, 25
V1.4.2
Verify that sign, range, and input validation techniques are used to prevent integer overflows.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 128, 129, 130, 131, 153, 184, 207, 242, 25, 272, 28
V1.4.3
Verify that dynamically allocated memory and resources are released, and that references or pointers to freed memory are removed or set to null to prevent dangling pointers and use-after-free vulnerabilities.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 129, 130, 131, 184, 207, 242
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.