3 ms·
I was more thinking of the case where >2GiB strings are not useful for normal use and the programmer does not anticipate them, but a malicious user can cause su
by pascal_cuoq 8y ago
I was more thinking of the case where >2GiB strings are not useful for normal use and the programmer does not anticipate them, but a malicious user can cause such strings to happen, for instance by sending them over the network in minutes or hours, causing unforeseen behavior.
- loeg 8y agoSure, that's a good point. However, while it may also be possible, in some code, for a malicious user to control the buffer size, the int precision argument, as used in this construct, derives from the buffer size, and not the input string. If the user can control the buffer size, then yes, we get the very undesireable buffer overflow via overflow from positive to negative[0]: A negative precision is taken as if the precision were omitted. [0]: snprintf(3) man page from linux