Author: jimtabor
Date: Mon Dec 19 16:37:44 2016
New Revision: 73470
URL:
http://svn.reactos.org/svn/reactos?rev=73470&view=rev
Log:
[User32]
- Patch by Roman Pi?l : Fix buffer overflow in EDIT_EM_ReplaceSel().
Modified:
trunk/reactos/win32ss/user/user32/controls/edit.c
Modified: trunk/reactos/win32ss/user/user32/controls/edit.c
URL:
http://svn.reactos.org/svn/reactos/trunk/reactos/win32ss/user/user32/contro…
==============================================================================
--- trunk/reactos/win32ss/user/user32/controls/edit.c [iso-8859-1] (original)
+++ trunk/reactos/win32ss/user/user32/controls/edit.c [iso-8859-1] Mon Dec 19 16:37:44
2016
@@ -2644,7 +2644,7 @@
if (es->buffer_limit < (tl - (e-s)))
strl = 0;
else
- strl = es->buffer_limit - (tl - (e-s));
+ strl = min(strl, es->buffer_limit - (tl - (e-s)));
}
if (!EDIT_MakeFit(es, tl - (e - s) + strl))