And kudos for the great job!
Thank you so much!
Thank you so much!
Hello, I found out a possible vulnerability regarding OTL_STRCAT_S in GCC/Linux branch. strncat’s third argument is the number of characters to append, not the total destination capacity. If dest already contains text, dest_sz - 1 can still exceed the remaining space and overflow the buffer. This affects the reported functions such as: otl_var_info_col(...) otl_var_info_var(...) A potential fix could be to change the definition of OTL_STRCAT_S(dest, dest_sz, src) from: OTL_STRCAT_S(dest, dest_sz,...