問題文
A user reads a report saying that a program crashed and then ran code supplied by an attacker after it received an input longer than expected. Which class of weakness is that and whose fix is it?
選択肢
- The report describes a buffer overflow and the fix belongs to the developer who must check the length of every input while the user can only apply the updates that the publisher releases.
- The report describes a buffer overflow and the fix belongs to the developer who must check the length of every input while the user can only apply the settings that the reader releases.
- The report describes a database overflow and the fix belongs to the developer who must encrypt the length of every input while the user can only apply the updates that the publisher releases.
- The report describes a database overflow and the fix belongs to the developer who must encrypt the length of every input while the user can only apply the settings that the reader releases.