TDropFilesActivator: DragQueryFile gets the buffer size in bytes instead of...
Brought to you by:
twm
TDropFilesActivator.WmDropFiles in src/u_dzVclUtils.pas declares arr: array[0..255] of Char and calls DragQueryFile(_Msg.wParam, i, PChar(@arr), SizeOf(arr)). The last parameter of DragQueryFile is the buffer size in characters, but SizeOf(arr) is in bytes: from Delphi 2009 on that is 512 for a buffer of 256 characters, so a dropped path longer than 255 characters overflows the buffer on the stack. Also, 256 characters is less than MAX_PATH.
Found by reading the code (by a GExperts session), not observed.
Fix: ask for the length first with DragQueryFile(h, i, nil, 0) and read into a string of that length, which also removes the length limit.
Fixed in revision #2384.