...
| Code Block |
|---|
struct buffer {
size_t size;
char buffer[50];
};
...
void func(struct buffer *buf) {
/* assuming sizeof(size_t) is 4, this equals 54 */
struct buffer *buf_cpy = malloc((sizeof(size_t)+(sizeof(char)*50))); /* assuming sizeof(size_t) is 4, this equals 54 */
if (buf_cpy == NULL) {
/* Handle malloc() error */
}
...
memcpy(buf_cpy, buf, sizeof(struct buffer)); /* with padding, sizeof(struct buffer) may equal 56, causing in a small buffer overflow */
memcpy(buf_cpy, buf, sizeof(struct buffer));
}
|
Compliant Solution
Structure padding should be accounted for when working with structures.
...