Description
strcat and wcscat append strings without checking the destination's remaining capacity.
Potential impact
- Buffer overflows and memory corruption
Remediation
Calculate the available destination capacity, then use a length-limited API or a safe string type.
Examples
Before
c
char dst[32] = "";
strcat(dst, user);
After
c
char dst[32] = "";
strncat(dst, user, sizeof(dst) - strlen(dst) - 1);
Explanation:
- Before: The user string is appended without considering the destination's remaining space.
- After: The append length is limited to the space remaining after the current string.