浏览代码

Actual buffer overflow bug found because of these fixes

Glenn Smith 7 年之前
父节点
当前提交
e03a86f75a
共有 1 个文件被更改,包括 2 次插入2 次删除
  1. 2 2
      Engine/source/console/fileSystemFunctions.cpp

+ 2 - 2
Engine/source/console/fileSystemFunctions.cpp

@@ -643,8 +643,8 @@ DefineEngineFunction(fileName, String, ( const char* fileName ),,
       name = szPathCopy;
    else
       name++;
-   char *ret = Con::getReturnBuffer(dStrlen(name));
-   dStrcpy(ret, name, dStrlen(name));
+   char *ret = Con::getReturnBuffer(dStrlen(name) + 1);
+   dStrcpy(ret, name, dStrlen(name) + 1);
    return ret;
 }