Unsafe use of sprintf

Unsafe use of sprintf

Description

sprintf does not accept an output buffer size, so the formatted result can exceed the destination buffer.

Potential impact

  • Stack or heap buffer overflows

Remediation

Use snprintf or a formatting API that enforces size limits.

Examples

Before

c
char buf[32];
sprintf(buf, "%s", name);

After

c
char buf[32];
snprintf(buf, sizeof(buf), "%s", name);

Explanation:

  • Before: The output length is unrestricted.
  • After: Specifying the destination size limits the output.

References