Integer Overflow in sprintf Buffer
This commit is contained in:
@ -62,8 +62,8 @@ string Drive::sCapacityToText()
|
||||
dSize /= 1000;
|
||||
u16UnitIndex++;
|
||||
}
|
||||
|
||||
sprintf(acBuffer, "%.*f %s", u16UnitIndex - 3, dSize, units[u16UnitIndex]);
|
||||
int precision = (u16UnitIndex >= 3) ? (u16UnitIndex - 3) : 0;
|
||||
sprintf(acBuffer, "%.*f %s", precision, dSize, units[u16UnitIndex]);
|
||||
return acBuffer;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user