CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium
A developer discovers that a legacy C application crashes when a user enters a string longer than the allocated 256-byte array for a login field, and further testing shows the crash can be leveraged to execute arbitrary code. Which vulnerability type does this describe?
- ASQL injection
- BCross-site scripting
- CRace condition
- DBuffer overflow
Show answer & explanationAnswer & explanation
Correct answer: D. Buffer overflow
Writing data beyond the boundary of a fixed-size buffer (256 bytes) can overwrite adjacent memory, including return addresses, allowing arbitrary code execution—this is the classic definition of a buffer overflow.
Why the other options are wrong
- A. SQL injection targets database queries, not memory allocation.
- B. XSS involves injecting script into web content viewed by other users, not memory corruption.
- C. Race conditions involve timing of concurrent operations, not buffer size.
Buffer Overflow
A vulnerability where data written to a fixed-size buffer exceeds its capacity, overwriting adjacent memory and potentially allowing code execution.
- Common in languages without automatic bounds checking (C/C++)
- Can overwrite the stack return address
- Mitigated by input validation, bounds checking, ASLR, and stack canaries
Memory trick: Overflow the cup and it spills onto the return address.