From ad07330e1a39bc4469aa9c085a34750f8c505266 Mon Sep 17 00:00:00 2001 From: Pablo Barciela Date: Sat, 23 Feb 2019 13:35:40 +0100 Subject: [Security] Use 'g_strlcpy' instead of 'strcpy' to avoid warnings with Clang Analyzer --- libcaja-private/caja-file-operations.c | 6 +++--- src/caja-sidebar-title.c | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/libcaja-private/caja-file-operations.c b/libcaja-private/caja-file-operations.c index 51481db0..a12d730c 100644 --- a/libcaja-private/caja-file-operations.c +++ b/libcaja-private/caja-file-operations.c @@ -6545,10 +6545,10 @@ mark_desktop_file_trusted (CommonJob *common, } if (!g_str_has_prefix (contents, "#!")) { - new_length = length + strlen (TRUSTED_SHEBANG); - new_contents = g_malloc (new_length); + new_length = length + strlen (TRUSTED_SHEBANG) + 1; + new_contents = g_malloc0 (new_length); - strcpy (new_contents, TRUSTED_SHEBANG); + g_strlcpy (new_contents, TRUSTED_SHEBANG, new_length); memcpy (new_contents + strlen (TRUSTED_SHEBANG), contents, length); diff --git a/src/caja-sidebar-title.c b/src/caja-sidebar-title.c index af9cb932..48eb8538 100644 --- a/src/caja-sidebar-title.c +++ b/src/caja-sidebar-title.c @@ -433,7 +433,7 @@ override_title_font (GtkWidget *widget, g_strreverse (tempsize); gchar tempfont [strlen (font)]; - strcpy (tempfont, font); + g_strlcpy (tempfont, font, sizeof (tempfont)); tempfont [strlen (font) - strlen (tempsize)] = 0; css = g_strdup_printf ("label { font-family: %s; font-size: %spt; }", tempfont, tempsize); -- cgit v1.2.1