CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsHard
A financial application allows users to enter a numeric value for a wire transfer amount. A tester enters a value larger than 2,147,483,647 into the field, and the resulting transfer processes for a negative amount instead. Which vulnerability MOST likely caused this behavior?
- AInteger overflow
- BLDAP injection
- CSession fixation
- DCross-site scripting
Show answer & explanationAnswer & explanation
Correct answer: A. Integer overflow
2,147,483,647 is the maximum value for a signed 32-bit integer; exceeding it causes the value to wrap around to a negative number, a classic integer overflow condition that can corrupt application logic like financial calculations.
Why the other options are wrong
- B. LDAP injection manipulates directory service queries, not numeric boundaries.
- C. Session fixation involves forcing a known session ID on a victim, unrelated to numeric input.
- D. XSS involves script injection into web pages, unrelated to numeric wraparound.
Integer Overflow
A vulnerability that occurs when an arithmetic operation produces a value outside the range representable by the allocated integer type, causing it to wrap around unexpectedly.
- Signed 32-bit max is 2,147,483,647
- Wraparound can flip a large positive number to negative
- Mitigated by input validation and using appropriately sized/unsigned data types
Memory trick: Push past the max and the number flips to the negative side.