diff options
author | Lubomir Rintel <lkundrak@v3.sk> | 2012-04-30 08:53:13 +0200 |
---|---|---|
committer | Lubomir Rintel <lkundrak@v3.sk> | 2013-10-29 16:30:52 +0100 |
commit | 6632a39575ae931f0532c84d78245c012fbb8773 (patch) | |
tree | bf12b60ceba4e0613ff72781798488bda92d1a34 | |
parent | cea8e7abbab7ea77de6090dc6dc43ac6a3eaca65 (diff) | |
download | dev86-6632a39575ae931f0532c84d78245c012fbb8773.tar.gz |
mkar: Fix off-by-one errors
There are off-by-one errors when filling the ar headers, the trailing nul
would overflow the target buffer.
-rw-r--r-- | ld/mkar.c | 12 |
1 files changed, 6 insertions, 6 deletions
@@ -52,12 +52,12 @@ char buf[128]; memset(&arbuf, ' ', sizeof(arbuf)); strcpy(buf, ptr); strcat(buf, "/ "); strncpy(arbuf.ar_name, buf, sizeof(arbuf.ar_name)); - - sprintf(arbuf.ar_date, "%-12ld", (long)st.st_mtime); - sprintf(arbuf.ar_uid, "%-6d", (int)(st.st_uid%1000000L)); - sprintf(arbuf.ar_gid, "%-6d", (int)(st.st_gid%1000000L)); - sprintf(arbuf.ar_mode, "%-8lo", (long)st.st_mode); - sprintf(arbuf.ar_size, "%-10ld", (long)st.st_size); + + snprintf(arbuf.ar_date, 12, "%-12ld", (long)st.st_mtime); + snprintf(arbuf.ar_uid, 6, "%-6d", (int)(st.st_uid%1000000L)); + snprintf(arbuf.ar_gid, 6, "%-6d", (int)(st.st_gid%1000000L)); + snprintf(arbuf.ar_mode, 8, "%-8lo", (long)st.st_mode); + snprintf(arbuf.ar_size, 10, "%-10ld", (long)st.st_size); memcpy(arbuf.ar_fmag, ARFMAG, sizeof(arbuf.ar_fmag)); if( fwrite(&arbuf, 1, sizeof(arbuf), fd) != sizeof(arbuf) ) |