Umbra Wiki weakness weakness/CWE-626
Back to wiki

CWE-626 — Null Byte Interaction Error (Poison Null Byte)

provenance: imported · CWE: CWE-626

CWE-626: Null Byte Interaction Error (Poison Null Byte)

MITRE CWE weakness

Kind Weakness
Abstraction Variant
Status Draft
Likelihood of exploit —

Description

The product does not properly handle null bytes or NUL characters when passing data between different representations or components.

A null byte (NUL character) can have different meanings across representations or languages. For example, it is a string terminator in standard C libraries, but Perl and PHP strings do not treat it as a terminator. When two representations are crossed - such as when Perl or PHP invokes underlying C functionality - this can produce an interaction error with unexpected results. Similar issues have been reported for ASP. Other interpreters written in C might also be affected. The poison null byte is frequently useful in path traversal attacks by terminating hard-coded extensions that are added to a filename. It can play a role in regular expression processing in PHP.

Common consequences

  • Integrity: Unexpected State

Mitigations

Implementation — Remove null bytes from all incoming strings.

References

  • CWE page: https://cwe.mitre.org/data/definitions/626.html
  • CWE list: https://cwe.mitre.org/data/index.html

See all 1,245 pages under Weakness classes (CWE) →

Related pages