json function could create overflow (#6460)
* jsonfix The use of sprintf to copy from a name to other name could create overflow, because source and destination have the same size, to avoid this I am changing the sprintf to snprintf' * jsonfix Use internal netdata snprintfz instead snprintf
thiagoftsm committed
Jul 17, 2019 at 16:15 UTC
a645b9129ae845caa4556e0f86392bd8d1343adf
1 file changed
+2
-2
libnetdata/json/json.c
+2
-2
@@ -319,8 +319,8 @@ size_t json_walk_array(char *js, jsmntok_t *t, size_t nest, size_t start, JSON_E
319
info("JSON: JSON walk_array ignoring element with name:%s fullname:%s",e->name, e->fullname);
320
continue;
321
}
322
- sprintf(ne.name, "%s[%lu]", e->name, i);
323
- sprintf(ne.fullname, "%s[%lu]", e->fullname, i);
322
+ snprintfz(ne.name, JSON_NAME_LEN, "%s[%lu]", e->name, i);
323
+ snprintfz(ne.fullname, JSON_FULLNAME_LEN, "%s[%lu]", e->fullname, i);
324
325
switch(t[start].type) {
326
case JSMN_PRIMITIVE: