Description
sprintf does not accept an output buffer size, so the formatted result can exceed the destination buffer.
Potential impact
- Stack or heap buffer overflows
Remediation
Use snprintf or a formatting API that enforces size limits.
Examples
Before
c
char buf[32];
sprintf(buf, "%s", name);
After
c
char buf[32];
snprintf(buf, sizeof(buf), "%s", name);
Explanation:
- Before: The output length is unrestricted.
- After: Specifying the destination size limits the output.