BOF
Term · Cybersecurity · MLC-T-CYB-000496
1. A condition at an interface under which more input can be placed into a buffer or data holding area than the capacity allocated, overwriting other information. Adversaries exploit such a condition to crash a system or to insert specially crafted code that allows them to gain control of the system.
2. A condition at an interface under which more input can be placed into a buffer or data holding area than the intended capacity allocated (due to insecure or unbound allocation parameters), which overwrites other information. Attackers exploit such a condition to crash a system or to insert specially crafted code that allows them to gain control of the system.
| Identifier | MLC-T-CYB-000496 |
|---|---|
| Field | Cybersecurity |
| Expansions | Buffer Overflow |
| References | NIST SP 800-82 Rev. 2 [Superseded] from NIST SP 800-28; NIST SP 800-82r3 from NIST SP 800-28 Version 2; NIST SP 800-28 Version 2; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-000496",
"term": "BOF",
"field": "Cybersecurity",
"definition": "1. A condition at an interface under which more input can be placed into a buffer or data holding area than the capacity allocated, overwriting other information. Adversaries exploit such a condition to crash a system or to insert specially crafted code that allows them to gain control of the system.\n\n2. A condition at an interface under which more input can be placed into a buffer or data holding area than the intended capacity allocated (due to insecure or unbound allocation parameters), which overwrites other information. Attackers exploit such a condition to crash a system or to insert specially crafted code that allows them to gain control of the system.",
"expansions": [
"Buffer Overflow"
],
"references": [
"NIST SP 800-82 Rev. 2 [Superseded] from NIST SP 800-28; NIST SP 800-82r3 from NIST SP 800-28 Version 2",
"NIST SP 800-28 Version 2",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/bof/"
}
Record 496 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.