understanding the dangers of sprintf(…)

前端 未结 8 1449

OWASP says:

\"C library functions such as strcpy (), strcat (), sprintf () and vsprintf () operate on null terminated strings and perform no bou

8条回答
  •  孤独总比滥情好
    2020-12-01 05:04

    I pretty much have stated a small example how you could get rid of the buffer size declaration for the sprintf (if you intended to, of course!) and no snprintf envolved ....

    Note: This is an APPEND/CONCATENATION example, take a look at here

提交回复
热议问题