Files
codeql/cpp/ql/src/Security/CWE/CWE-120/UnboundedWrite.c
2018-08-02 17:53:23 +01:00

9 lines
232 B
C

void congratulateUser(const char *userName)
{
char buffer[80];
// BAD: this could overflow the buffer if the UserName is long
sprintf(buffer, "Congratulations, %s!", userName);
MessageBox(hWnd, buffer, "New Message", MB_OK);
}