buffer overflow
Term · Cybersecurity · MLC-T-CYB-000513
1. A condition at an interface under which more input can be placed into a buffer or data holding area than the intended capacity allocated (due to insecure or unbound allocation parameters), which overwrites other information. Attackers exploit such a condition to crash a system or to insert specially crafted code that allows them to gain control of the system.
2. A condition at an interface under which more input can be placed into a buffer or data holding area than the capacity allocated, overwriting other information. Adversaries exploit such a condition to crash a system or to insert specially crafted code that allows them to gain control of the system.
| Identifier | MLC-T-CYB-000513 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | BOF |
| References | CNSSI 4009-2022 from CNSSI 1011 (adapted); NIST SP 800-28 Version 2; NIST SP 800-82r3 from NIST SP 800-28 Version 2; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-000513",
"term": "buffer overflow",
"field": "Cybersecurity",
"definition": "1. A condition at an interface under which more input can be placed into a buffer or data holding area than the intended capacity allocated (due to insecure or unbound allocation parameters), which overwrites other information. Attackers exploit such a condition to crash a system or to insert specially crafted code that allows them to gain control of the system.\n\n2. A condition at an interface under which more input can be placed into a buffer or data holding area than the capacity allocated, overwriting other information. Adversaries exploit such a condition to crash a system or to insert specially crafted code that allows them to gain control of the system.",
"abbreviation": "BOF",
"references": [
"CNSSI 4009-2022 from CNSSI 1011 (adapted); NIST SP 800-28 Version 2",
"NIST SP 800-82r3 from NIST SP 800-28 Version 2",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/buffer-overflow/"
}
Record 513 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.