Fixed unsafe string copy and concat in fileio.c.

Per warnings from flawfinder: "Does not check for buffer overflows when
copying to destination [MS-banned] (CWE-120). Consider using snprintf,
strcpy_s, or strlcpy (warning: strncpy easily misused).".

Replaced called to strcpy and strcat in `fileio.c` to calls with a
specified size (`strncpy` and `strncat`).

Tested the changes on OSX, Linux, Windows.
On OSX + Linux, changes were tested with ASAN. The following flags were
used: 'check_initialization_order=1:strict_init_order=1:detect_odr_violation=1:detect_stack_use_after_return=1'

To reproduce warning:
./flawfinder.py ./programs/fileio.c
This commit is contained in:
Eden Zik
2018-08-20 22:15:24 -04:00
parent 973a8d42c7
commit 78af534f82
2 changed files with 3 additions and 2 deletions
+1
View File
@@ -26,6 +26,7 @@ invalidDictionaries
checkTag
zcat
zstdcat
tm
# Tmp test directory
zstdtest