When a file descriptor or handle is not released after use (typically by explicitly closing it), attackers can cause a denial of service by consuming all available file descriptors/handles, or otherwise preventing other system processes from obtaining their own file descriptors/handles.
Relevant to the view "Research Concepts" (CWE-1000)
自然
Type
ID
姓名
Childof
根据- a weakness that is still mostly independent of a resource or technology, but with sufficient details to provide specific methods for detection and prevention. Base level weaknesses typically describe issues in terms of 2 or 3 of the following dimensions: behavior, property, technology, language, and resource.
班级- a weakness that is described in a very abstract fashion, typically independent of any specific language or technology. More specific than a Pillar Weakness, but more general than a Base Weakness. Class level weaknesses typically describe issues in terms of 1 or 2 of the following dimensions: behavior, property, and resource.
班级- a weakness that is described in a very abstract fashion, typically independent of any specific language or technology. More specific than a Pillar Weakness, but more general than a Base Weakness. Class level weaknesses typically describe issues in terms of 1 or 2 of the following dimensions: behavior, property, and resource.
When the current levels get close to the maximum that is defined for the application (seeCWE-770),然后将更多资源的分配限制为特权用户;或者,开始为较弱的用户释放资源。尽管这种缓解措施可以保护系统免受攻击,但它不一定会阻止攻击者对其他用户产生不利影响。
[REF-62] Mark Dowd, John McDonald and Justin Schuh. "The Art of Software Security Assessment". Chapter 10, "File Descriptor Leaks", Page 582. 1st Edition. Addison Wesley. 2006.
内容历史记录
Submissions
Submission Date
提交者
Organization
2009-05-13
CWE内容团队
MITER
修改
修改日期
Modifier
Organization
2009-12-28
CWE内容团队
MITER
更新了观察到的examples
2010-04-05
CWE内容团队
MITER
updated Potential_Mitigations
2011-06-01
CWE内容团队
MITER
updated Common_Consequences
2012-05-11
CWE内容团队
MITER
updated References, Relationships
2012-10-30
CWE内容团队
MITER
updated Potential_Mitigations
2014-07-30
CWE内容团队
MITER
updated Relationships, Taxonomy_Mappings
2015-12-07
CWE内容团队
MITER
updated Relationships
2017-11-08
CWE内容团队
MITER
更新的likelihood_of_exploit,关系,分类_mappings
2019-01-03
CWE内容团队
MITER
更新的common_cconsquences,关系,theoricenity_notes
2019-06-20
CWE内容团队
MITER
updated Relationships
2020-02-24
CWE内容团队
MITER
updated Relationships, Taxonomy_Mappings
2020-08-20
CWE内容团队
MITER
updated Relationships
2020-12-10
CWE内容团队
MITER
updated Relationships
2022-10-13
CWE内容团队
MITER
updated Relationships, Taxonomy_Mappings
2023-01-31
CWE内容团队
MITER
更新的描述
More information is available — Please select a different filter.