From 429b07a95d4dc82f5e4cf814d7f9ca459332f0bb Mon Sep 17 00:00:00 2001 From: Ted Reed Date: Sun, 15 Mar 2020 20:35:46 -0400 Subject: [PATCH] Add execve to CommandExecution --- cpp/ql/src/semmle/code/cpp/security/CommandExecution.qll | 2 ++ 1 file changed, 2 insertions(+) diff --git a/cpp/ql/src/semmle/code/cpp/security/CommandExecution.qll b/cpp/ql/src/semmle/code/cpp/security/CommandExecution.qll index c7bea7eede7..48fb60442c1 100644 --- a/cpp/ql/src/semmle/code/cpp/security/CommandExecution.qll +++ b/cpp/ql/src/semmle/code/cpp/security/CommandExecution.qll @@ -99,6 +99,8 @@ class ArrayExecFunctionCall extends FunctionCall { getTarget().hasGlobalName("execv") or getTarget().hasGlobalName("execvp") or getTarget().hasGlobalName("execvpe") or + getTarget().hasGlobalName("execve") or + getTarget().hasGlobalName("fexecve") or // Windows variants getTarget().hasGlobalName("_execv") or getTarget().hasGlobalName("_execve") or