Flawfinder version 2.0.10, (C) 2001-2019 David A. Wheeler. Number of rules (primarily dangerous function names) in C/C++ ruleset: 223 Examining data/cython-0.29.21/tests/buffers/bufaccess.h Examining data/cython-0.29.21/tests/compile/nogil.h Examining data/cython-0.29.21/tests/compile/cpp_enums.h Examining data/cython-0.29.21/tests/compile/point.h Examining data/cython-0.29.21/tests/compile/crunchytype.h Examining data/cython-0.29.21/tests/compile/cheese.h Examining data/cython-0.29.21/tests/compile/hinsen1.h Examining data/cython-0.29.21/tests/compile/food.h Examining data/cython-0.29.21/tests/compile/altet1.h Examining data/cython-0.29.21/tests/compile/excvalcheck.h Examining data/cython-0.29.21/tests/compile/templates.h Examining data/cython-0.29.21/tests/compile/belchenko2.h Examining data/cython-0.29.21/tests/compile/cpp_nogil.h Examining data/cython-0.29.21/tests/compile/operators.h Examining data/cython-0.29.21/tests/compile/cast_ctypedef_array_T518_helper.h Examining data/cython-0.29.21/tests/run/includes/b.h Examining data/cython-0.29.21/tests/run/includes/c.h Examining data/cython-0.29.21/tests/run/includes/a.h Examining data/cython-0.29.21/tests/run/includes/d.h Examining data/cython-0.29.21/tests/run/includes/e.h Examining data/cython-0.29.21/tests/run/cpp_template_ref_args.h Examining data/cython-0.29.21/tests/run/cpp_unordered_map_helper.h Examining data/cython-0.29.21/tests/run/curiously_recurring_template_pattern_GH1458_suport.h Examining data/cython-0.29.21/tests/run/cpp_nested_classes_support.h Examining data/cython-0.29.21/tests/run/crashT245.h Examining data/cython-0.29.21/tests/run/types.h Examining data/cython-0.29.21/tests/run/complex_numbers_c99_T398.h Examining data/cython-0.29.21/tests/run/arithmetic_analyse_types_helper.h Examining data/cython-0.29.21/tests/run/complex_numbers_c89_T398.h Examining data/cython-0.29.21/tests/run/struct_conversion_extern_header.h Examining data/cython-0.29.21/tests/run/cpp_smart_ptr_helper.h Examining data/cython-0.29.21/tests/run/cpp_template_functions_helper.h Examining data/cython-0.29.21/tests/run/if_else_expr_cpp_helper.h Examining data/cython-0.29.21/tests/run/verbatiminclude.h Examining data/cython-0.29.21/tests/run/cpp_function_lib.h Examining data/cython-0.29.21/tests/run/complex_numbers_cxx_T398.h Examining data/cython-0.29.21/tests/run/define_macro_helper.h Examining data/cython-0.29.21/tests/run/cpp_operators_helper.h Examining data/cython-0.29.21/tests/run/cpp_function_lib.cpp Examining data/cython-0.29.21/tests/run/cpp_exceptions_helper.h Examining data/cython-0.29.21/tests/run/shapes.h Examining data/cython-0.29.21/tests/run/complex_int_T446_fix.h Examining data/cython-0.29.21/tests/run/cpp_nonstdint.h Examining data/cython-0.29.21/tests/run/ctypedef_int_types_chdr_T333.h Examining data/cython-0.29.21/tests/run/cpp_template_subclasses_helper.h Examining data/cython-0.29.21/tests/run/cpp_operator_exc_handling_helper.hpp Examining data/cython-0.29.21/tests/run/cpp_iterators_simple.h Examining data/cython-0.29.21/tests/run/cpp_templates_helper.h Examining data/cython-0.29.21/tests/run/cpp_namespaces_helper.h Examining data/cython-0.29.21/tests/run/cpp_exceptions_nogil_helper.h Examining data/cython-0.29.21/tests/run/external_defs.h Examining data/cython-0.29.21/tests/wrappers/cpp_overload_wrapper_lib.h Examining data/cython-0.29.21/tests/wrappers/cppwrap_lib.h Examining data/cython-0.29.21/tests/wrappers/cppwrap_lib.cpp Examining data/cython-0.29.21/tests/wrappers/cpp_references_helper.h Examining data/cython-0.29.21/tests/wrappers/cpp_overload_wrapper_lib.cpp Examining data/cython-0.29.21/tests/memoryview/bufaccess.h Examining data/cython-0.29.21/Cython/Utility/Embed.c Examining data/cython-0.29.21/Cython/Utility/ModuleSetupCode.c Examining data/cython-0.29.21/Cython/Utility/Optimize.c Examining data/cython-0.29.21/Cython/Utility/Builtins.c Examining data/cython-0.29.21/Cython/Utility/Capsule.c Examining data/cython-0.29.21/Cython/Utility/CppSupport.cpp Examining data/cython-0.29.21/Cython/Utility/Buffer.c Examining data/cython-0.29.21/Cython/Utility/Profile.c Examining data/cython-0.29.21/Cython/Utility/StringTools.c Examining data/cython-0.29.21/Cython/Utility/ObjectHandling.c Examining data/cython-0.29.21/Cython/Utility/Exceptions.c Examining data/cython-0.29.21/Cython/Utility/AsyncGen.c Examining data/cython-0.29.21/Cython/Utility/CMath.c Examining data/cython-0.29.21/Cython/Utility/CythonFunction.c Examining data/cython-0.29.21/Cython/Utility/FunctionArguments.c Examining data/cython-0.29.21/Cython/Utility/ImportExport.c Examining data/cython-0.29.21/Cython/Utility/Printing.c Examining data/cython-0.29.21/Cython/Utility/Coroutine.c Examining data/cython-0.29.21/Cython/Utility/TypeConversion.c Examining data/cython-0.29.21/Cython/Utility/Complex.c Examining data/cython-0.29.21/Cython/Utility/ExtensionTypes.c Examining data/cython-0.29.21/Cython/Utility/arrayarray.h Examining data/cython-0.29.21/Cython/Utility/CommonStructures.c Examining data/cython-0.29.21/Cython/Utility/Overflow.c Examining data/cython-0.29.21/Cython/Utility/TestUtilityLoader.c Examining data/cython-0.29.21/Cython/Utility/MemoryView_C.c Examining data/cython-0.29.21/Cython/Debugger/Tests/cfuncs.h Examining data/cython-0.29.21/Cython/Debugger/Tests/cfuncs.c Examining data/cython-0.29.21/Demos/libraries/mymath.c Examining data/cython-0.29.21/Demos/libraries/mymath.h Examining data/cython-0.29.21/Demos/callback/cheesefinder.c Examining data/cython-0.29.21/Demos/callback/cheesefinder.h Examining data/cython-0.29.21/docs/examples/tutorial/string/someheader.h Examining data/cython-0.29.21/docs/examples/tutorial/clibraries/c-algorithms/src/queue.h Examining data/cython-0.29.21/docs/examples/userguide/wrapping_CPlusPlus/Rectangle.h Examining data/cython-0.29.21/docs/examples/userguide/wrapping_CPlusPlus/Rectangle.cpp Examining data/cython-0.29.21/docs/examples/userguide/memoryviews/C_func_file.h Examining data/cython-0.29.21/docs/examples/userguide/memoryviews/C_func_file.c Examining data/cython-0.29.21/docs/examples/userguide/external_C_code/marty.c Examining data/cython-0.29.21/docs/examples/userguide/sharing_declarations/lunch.h FINAL RESULTS: data/cython-0.29.21/Cython/Utility/MemoryView_C.c:458:5: [4] (format) vsnprintf: If format strings can be influenced by an attacker, they can be exploited, and note that sprintf variations do not always \0-terminate (CWE-134). Use a constant for the format specification. vsnprintf(msg, 200, fmt, vargs); data/cython-0.29.21/Cython/Utility/TypeConversion.c:191:5: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(__PYX_DEFAULT_STRING_ENCODING, default_encoding_c); data/cython-0.29.21/Cython/Utility/ExtensionTypes.c:248:18: [3] (random) setstate: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. if (!setstate) PyErr_Clear(); data/cython-0.29.21/Cython/Utility/ExtensionTypes.c:249:18: [3] (random) setstate: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. if (!setstate || __Pyx_setup_reduce_is_named(setstate, PYIDENT("__setstate_cython__"))) { data/cython-0.29.21/Cython/Utility/ExtensionTypes.c:249:58: [3] (random) setstate: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. if (!setstate || __Pyx_setup_reduce_is_named(setstate, PYIDENT("__setstate_cython__"))) { data/cython-0.29.21/Cython/Utility/ExtensionTypes.c:254:29: [3] (random) setstate: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. } else if (!setstate || PyErr_Occurred()) { data/cython-0.29.21/Cython/Utility/ExtensionTypes.c:277:16: [3] (random) setstate: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. Py_XDECREF(setstate); data/cython-0.29.21/Cython/Utility/Buffer.c:868:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char string[3]; data/cython-0.29.21/Cython/Utility/CythonFunction.c:947:9: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. memcpy(meth->func.defaults, func->func.defaults, func->func.defaults_size); data/cython-0.29.21/Cython/Utility/ImportExport.c:334:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char warning[200]; data/cython-0.29.21/Cython/Utility/MemoryView_C.c:451:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char msg[200]; data/cython-0.29.21/Cython/Utility/ModuleSetupCode.c:1121:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ctversion[4], rtversion[4]; data/cython-0.29.21/Cython/Utility/ModuleSetupCode.c:1125:9: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char message[200]; data/cython-0.29.21/Cython/Utility/StringTools.c:857:13: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. memcpy((char *)result_udata + char_pos * result_ukind, udata, (size_t) (ulength * result_ukind)); data/cython-0.29.21/Cython/Utility/TypeConversion.c:138:9: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ascii_chars[128]; data/cython-0.29.21/Cython/Utility/TypeConversion.c:653:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static const char DIGIT_PAIRS_10[2*10*10+1] = { data/cython-0.29.21/Cython/Utility/TypeConversion.c:666:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static const char DIGIT_PAIRS_8[2*8*8+1] = { data/cython-0.29.21/Cython/Utility/TypeConversion.c:677:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. static const char DIGITS_HEX[2*16+1] = { data/cython-0.29.21/Cython/Utility/TypeConversion.c:711:5: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char digits[sizeof({{TYPE}})*3+2]; data/cython-0.29.21/docs/examples/userguide/external_C_code/marty.c:9:14: [2] (integer) atoi: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). car.speed = atoi(argv[1]); data/cython-0.29.21/tests/run/cpp_nonstdint.h:6:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char bytes[N]; data/cython-0.29.21/tests/run/cpp_nonstdint.h:127:5: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. memcpy(dst + dst_offset, src + src_offset, src_len); data/cython-0.29.21/Cython/Utility/Embed.c:78:22: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t argsize = strlen(arg); data/cython-0.29.21/Cython/Utility/Embed.c:111:15: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). argsize = strlen(arg) + 1; data/cython-0.29.21/Cython/Utility/Embed.c:156:30: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). res = (wchar_t *)malloc((strlen(arg)+1)*sizeof(wchar_t)); data/cython-0.29.21/Cython/Utility/StringTools.c:466:23: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). size_t slen = strlen(cstring); data/cython-0.29.21/Cython/Utility/TypeConversion.c:51:87: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). #define __Pyx_PyByteArray_FromString(s) PyByteArray_FromStringAndSize((const char*)s, strlen((const char*)s)) data/cython-0.29.21/Cython/Utility/TypeConversion.c:189:52: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). __PYX_DEFAULT_STRING_ENCODING = (char*) malloc(strlen(default_encoding_c) + 1); data/cython-0.29.21/Cython/Utility/TypeConversion.c:206:65: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). return __Pyx_PyUnicode_FromStringAndSize(c_str, (Py_ssize_t)strlen(c_str)); ANALYSIS SUMMARY: Hits = 29 Lines analyzed = 20060 in approximately 4.43 seconds (4533 lines/second) Physical Source Lines of Code (SLOC) = 15809 Hits@level = [0] 3 [1] 7 [2] 15 [3] 5 [4] 2 [5] 0 Hits@level+ = [0+] 32 [1+] 29 [2+] 22 [3+] 7 [4+] 2 [5+] 0 Hits/KSLOC@level+ = [0+] 2.02416 [1+] 1.8344 [2+] 1.39161 [3+] 0.442786 [4+] 0.12651 [5+] 0 Dot directories skipped = 1 (--followdotdir overrides) Minimum risk level = 1 Not every hit is necessarily a security vulnerability. There may be other security vulnerabilities; review your code! See 'Secure Programming HOWTO' (https://dwheeler.com/secure-programs) for more information.