From 9b951b4dd8502532ad8e8703230dfc69ca4c876d Mon Sep 17 00:00:00 2001 From: Gregory Nutt Date: Tue, 11 Oct 2016 17:35:31 -0600 Subject: [PATCH] apps/nshlib: nsh_getdirpath(), use snprint instead of sprintf to avoid possibility of buffer overrun. Noted by Chung Hwan Kim. --- nshlib/nsh_fscmds.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/nshlib/nsh_fscmds.c b/nshlib/nsh_fscmds.c index 7f13920a6..44f54dff1 100644 --- a/nshlib/nsh_fscmds.c +++ b/nshlib/nsh_fscmds.c @@ -114,11 +114,11 @@ static char *nsh_getdirpath(FAR struct nsh_vtbl_s *vtbl, if (strcmp(path, "/") == 0) { - sprintf(vtbl->iobuffer, "/%s", file); + snprintf(vtbl->iobuffer, IOBUFFERSIZE, "/%s", file); } else { - sprintf(vtbl->iobuffer, "%s/%s", path, file); + snprintf(vtbl->iobuffer, IOBUFFERSIZE, "%s/%s", path, file); } vtbl->iobuffer[PATH_MAX] = '\0';