Use size-bounded versions of sprintf, strcpy and strcat
To avoid potential buffer overflows and to make static analyzers happy. Fixed CWE-120: - sprintf: does not check for buffer overflows - strcpy: does not check for buffer overflows when copying to destination - strcat: does not check for buffer overflows when concatenating to destination Closes #7534 NO_DOC=refactoring NO_TEST=refactoring NO_CHANGELOG=refactoring
Showing
- src/box/lua/serialize_lua.c 2 additions, 2 deletionssrc/box/lua/serialize_lua.c
- src/box/sql.c 3 additions, 2 deletionssrc/box/sql.c
- src/box/sql/build.c 5 additions, 5 deletionssrc/box/sql/build.c
- src/box/sql/select.c 2 additions, 1 deletionsrc/box/sql/select.c
- src/box/sql/tokenize.c 1 addition, 1 deletionsrc/box/sql/tokenize.c
- src/box/xlog.c 1 addition, 2 deletionssrc/box/xlog.c
- src/box/xrow.c 2 additions, 1 deletionsrc/box/xrow.c
- src/lib/core/popen.c 4 additions, 2 deletionssrc/lib/core/popen.c
- src/lib/core/sio.c 1 addition, 1 deletionsrc/lib/core/sio.c
- src/lib/core/util.c 2 additions, 2 deletionssrc/lib/core/util.c
- src/lib/tzcode/localtime.c 6 additions, 3 deletionssrc/lib/tzcode/localtime.c
- src/lib/tzcode/strptime.c 2 additions, 2 deletionssrc/lib/tzcode/strptime.c
- src/lib/tzcode/timezone.c 1 addition, 1 deletionsrc/lib/tzcode/timezone.c
- src/proc_title.c 2 additions, 1 deletionsrc/proc_title.c
- src/systemd.c 1 addition, 1 deletionsrc/systemd.c
Loading
Please register or sign in to comment