GaloisInc / BESSPIN-Tool-Suite

The core tool of the BESSPIN Framework.
Other
5 stars 2 forks source link

CWE-681 Question #1048

Closed njshanahan closed 3 years ago

njshanahan commented 3 years ago

Should a score be included for numeric error CWE-681? I see in NumericErrors.cfr that it's considered covered by tests 192, 194, 195, or 196 but it isn't given a dedicated score in the resulting log/csv files. It does, however, appear in ssithCWEList.md as one of fifteen numeric errors, so I'm wondering if that will be needed to accurately calculate a coverage percentage.

Tagging @austinhroach for awareness. Once again, I appreciate the help!

rtadros125 commented 3 years ago

This was resolved in #1006 which is included in Release 4.2 (The release is technically out since Friday. The release notes and the release email should be sent out anytime now). Please update the tool's reference to point to the newest master tip.

njshanahan commented 3 years ago

@rtadros125 Thanks!