undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,3 @@
import java.io.*;
public interface AnotherInterface extends Serializable {}

View file

@ -0,0 +1,64 @@
/*
@test
@key headful
@bug 4932376
@summary verifies that data transfer within one JVM works correctly if
the transfer data was created with a custom class loader.
@author das@sparc.spb.su area=datatransfer
@library ../../regtesthelpers
@build TransferableList AnotherInterface CopyClassFile CustomClassLoaderTransferTest
@run main CopyClassFile -r ListInterface subdir/
@run main CopyClassFile -r TransferableList subdir/
@run main CustomClassLoaderTransferTest
*/
import java.awt.*;
import java.awt.datatransfer.*;
import java.io.*;
import java.net.URL;
import java.net.URLClassLoader;
public class CustomClassLoaderTransferTest {
public static class DFTransferable implements Transferable {
private final DataFlavor df;
private final Object obj;
public DFTransferable(DataFlavor df, Object obj) {
this.df = df;
this.obj = obj;
}
@Override
public Object getTransferData(DataFlavor flavor)
throws UnsupportedFlavorException, IOException {
if (df.equals(flavor)) {
return obj;
} else {
throw new UnsupportedFlavorException(flavor);
}
}
@Override
public DataFlavor[] getTransferDataFlavors(){
return new DataFlavor[] { df };
}
@Override
public boolean isDataFlavorSupported(DataFlavor flavor) {
return df.equals(flavor);
}
}
public static void main(String[] args) throws Exception {
Clipboard c = Toolkit.getDefaultToolkit().getSystemClipboard();
URL url = new File("./subdir/").toURL();
ClassLoader classLoader = new URLClassLoader(new URL[] { url },
CustomClassLoaderTransferTest.class.getClassLoader());
Class clazz = Class.forName("TransferableList", true, classLoader);
DataFlavor df = new DataFlavor(clazz, "Transferable List");
Object obj = clazz.newInstance();
Transferable t = new DFTransferable(df, obj);
c.setContents(t, null);
Transferable ct = c.getContents(null);
ct.getTransferData(df);
}
}

View file

@ -0,0 +1,30 @@
import java.io.Serializable;
import java.lang.reflect.InvocationHandler;
import java.lang.reflect.Method;
import java.lang.reflect.Proxy;
import java.util.ArrayList;
public class TransferableList extends ArrayList {
private static class NullInvocationHandler implements InvocationHandler, Serializable {
public Object invoke(Object proxy, Method method, Object[] args)
throws Throwable {
throw new Error("UNIMPLEMENTED");
}
}
public TransferableList() {
try {
InvocationHandler handler = new NullInvocationHandler();
Class<?> proxyClass = Proxy.getProxyClass(
ListInterface.class.getClassLoader(),
new Class[] { ListInterface.class, AnotherInterface.class });
AnotherInterface obj = (AnotherInterface) proxyClass.
getConstructor(new Class[]{InvocationHandler.class}).
newInstance(handler);
} catch (Exception e) {
e.printStackTrace();
}
}
}
interface ListInterface extends Serializable {}