Unsafe use of gets

Unsafe use of gets

Description

gets cannot limit input length, so input can easily exceed the destination buffer.

Potential impact

  • Stack buffer overflows, crashes, or code execution

Remediation

Use an API that accepts the destination buffer's size, such as fgets.

Examples

Before

c
char buf[32];
gets(buf);

After

c
char buf[32];
fgets(buf, sizeof(buf), stdin);

Explanation:

  • Before: Input is written to the buffer without a length limit.
  • After: The destination array's size is passed as the limit.

References