diff options
author | Tomasz Kramkowski <tk@the-tk.com> | 2016-12-29 19:42:41 +0100 |
---|---|---|
committer | Tomasz Kramkowski <tk@the-tk.com> | 2016-12-29 19:42:41 +0100 |
commit | 2b5c1b4b133a97a46354142aa8ab0d9e79bc70a4 (patch) | |
tree | 208946c62eff13e9e6654a146cf8ff38ea7796b1 /UptimeMeter.c | |
parent | 8af4d9f453ffa2209e486418811f7652822951c6 (diff) |
Replace all uses of sprintf with snprintf
In all the cases where sprintf was being used within htop, snprintf
could have been used. This patch replaces all uses of sprintf with
snprintf which makes sure that if a buffer is too small to hold the
resulting string, the string is simply cut short instead of causing
a buffer overflow which leads to undefined behaviour.
`sizeof(variable)` was used in these cases, as opposed to `sizeof
variable` which is my personal preference because `sizeof(variable)`
was already used in one way or another in other parts of the code.
Diffstat (limited to 'UptimeMeter.c')
-rw-r--r-- | UptimeMeter.c | 6 |
1 files changed, 3 insertions, 3 deletions
diff --git a/UptimeMeter.c b/UptimeMeter.c index d20c4797..2fe603ae 100644 --- a/UptimeMeter.c +++ b/UptimeMeter.c @@ -33,11 +33,11 @@ static void UptimeMeter_updateValues(Meter* this, char* buffer, int len) { } char daysbuf[15]; if (days > 100) { - sprintf(daysbuf, "%d days(!), ", days); + snprintf(daysbuf, sizeof(daysbuf), "%d days(!), ", days); } else if (days > 1) { - sprintf(daysbuf, "%d days, ", days); + snprintf(daysbuf, sizeof(daysbuf), "%d days, ", days); } else if (days == 1) { - sprintf(daysbuf, "1 day, "); + snprintf(daysbuf, sizeof(daysbuf), "1 day, "); } else { daysbuf[0] = '\0'; } |