Symbolic Name not Mapping to Correct Object |
Weakness ID: 386 (Weakness Base) | Status: Draft |
Description Summary
A constant symbolic reference to an object is used, even though the reference can resolve to a different object over time.
Scope | Effect |
---|---|
Access Control | The attacker can gain access to otherwise unauthorized resources. |
Authorization | Race conditions such as this kind may be employed to gain read or write access to resources not normally readable or writable by the user in question. |
Integrity | The resource in question, or other resources (through the corrupted one) may be changed in undesirable ways by a malicious user. |
Accountability | If a file or other resource is written in this method, as opposed to a valid way, logging of the activity may not occur. |
Non-Repudiation | In some cases it may be possible to delete files that a malicious user might not otherwise have access to -- such as log files. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 361 | Time and State | Development Concepts (primary)699 |
ChildOf | ![]() | 706 | Use of Incorrectly-Resolved Name or Reference | Research Concepts (primary)1000 |
PeerOf | ![]() | 367 | Time-of-check Time-of-use (TOCTOU) Race Condition | Research Concepts1000 |
PeerOf | ![]() | 486 | Comparison of Classes by Name | Research Concepts1000 |
PeerOf | ![]() | 610 | Externally Controlled Reference to a Resource in Another Sphere | Research Concepts1000 |
RequiredBy | ![]() | 61 | UNIX Symbolic Link (Symlink) Following | Research Concepts1000 |
Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
---|---|---|---|
CLASP | Symbolic name not mapping to correct object |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
CLASP | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-07-01 | Eric Dalci | Cigital | External | |
updated Time of Introduction | ||||
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Common Consequences, Relationships, Taxonomy Mappings |