CERT
 
Publications Catalog Historical Documents Authorized Users of "CERT" US-CERT Vulnerability Notes Database CERT Statistics Vulnerability Disclosure Policy CERT Knowledgebase Courses FIRST conference 2008 sponsor Link to US-CERT cylab
 

Managed String Library

The managed string library was developed in response to the need for a string library that can improve the quality and security of newly developed C-language programs while eliminating obstacles to widespread adoption and possible standardization. As the name implies, the managed string library is based on a dynamic approach; memory is allocated and reallocated as required. This approach eliminates the possibility of unbounded copies, null-termination errors, and truncation by ensuring that there is always adequate space available for the resulting string (including the terminating null character). The one exception is if memory is exhausted; that is treated as an error condition. In this way, the managed string library accomplishes the goal of indicating either success or failure. The managed string library also protects against improper data sanitization by (optionally) ensuring that all characters in a string belong to a predefined set of "safe" characters.

Accessing the library

A beta implementation of the managed string library is available for download.

Additional information

The following documents contain more detailed information about this project:


Copyright 2006 Carnegie Mellon University
CERT® and CERT Coordination Center® are registered in the U.S. Patent and Trademark office.

Disclaimers and copyright information

Last updated February 28, 2006