Description
strcpy and wcscpy do not check whether the source string is longer than the destination buffer can hold.
Potential impact
- Buffer overflows, crashes, or code execution
Remediation
Limit the copy length to the destination's capacity, or use a safe string type.
Examples
Before
c
char dst[32];
strcpy(dst, user);
After
c
char dst[32];
snprintf(dst, sizeof(dst), "%s", user);
Explanation:
- Before: The source length is not checked against the destination size.
- After: The destination size bounds the copy.