From: Alex Riesen Date: Wed, 09 Jun 2010 12:44:51 GMT Subject: Re: [PATCH] Use strncpy to protect from buffer overruns. Message-ID: In-Reply-To: <1276078921-25429-1-git-send-email-smichalske@gmail.com> On Wed, Jun 9, 2010 at 12:22, Steven Michalske wrote: > is_git_directory() uses strcpy with pointer arithmitic, protect it from > overflowing.  Even though we currently protect higher up when we have the > environment variable path passed in, we should protect the calls here. Why? The function is static. > -       strcpy(path, suspect); > +       path[sizeof(path) - 1] = '\0'; > + > +       strncpy(path, suspect, sizeof(path) - 1); And we have strlcpy for such things.