From 3300d5d47a054bd2615db0f99e1478808ec88032 Mon Sep 17 00:00:00 2001 From: sin Date: Sat, 2 Jan 2016 09:44:06 +0000 Subject: [PATCH] ed: Use strlcpy/strlcat to construct the scratch filename --- ed.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/ed.c b/ed.c index 62f8477..ed55581 100644 --- a/ed.c +++ b/ed.c @@ -335,12 +335,12 @@ setscratch() clearundo(); if ((dir = getenv("TMPDIR")) == NULL) dir = "/tmp/"; - if (strlen(dir) + sizeof("ed.XXXXXX") > FILENAME_MAX) - error("incorrect scratch file name"); - strcat(strcpy(tmpname, dir), "ed.XXXXX"); - if ((scratch = mkstemp(tmpname)) < 0) { + if (strlcpy(tmpname, dir, sizeof(tmpname)) >= sizeof(tmpname)) + error("scratch file name too long"); + if (strlcat(tmpname, "ed.XXXXXX", sizeof(tmpname)) >= sizeof(tmpname)) + error("scratch file name too long"); + if ((scratch = mkstemp(tmpname)) < 0) error("failed to create scratch file"); - } if ((k = makeline("", NULL))) error("input/output error in scratch file"); relink(k, k, k, k);