Menu

#25 unsafe snprintf() usage

closed
None
Bug Report
2015-11-25
2015-07-08
No

The return value of snprintf() is frequently ignored and assumed to be non-negative and less than the buffer length. These assumptions might not always be true, which could cause undesirable behavior (possibly exploitable).

Discussion

  • Richard Hansen

    Richard Hansen - 2015-07-08
    • status: in-progress --> waiting-for-review
     
  • Richard Hansen

    Richard Hansen - 2015-07-09
    • status: waiting-for-review --> closed
     
  • Richard Hansen

    Richard Hansen - 2015-07-09

    merged

     
  • David Mandelberg

     
  • David Mandelberg

    Migrated to github.