Author: jimtabor Date: Mon Dec 19 16:37:44 2016 New Revision: 73470
URL: http://svn.reactos.org/svn/reactos?rev=73470&view=rev Log: [User32] - Patch by Roman Pi?l : Fix buffer overflow in EDIT_EM_ReplaceSel().
Modified: trunk/reactos/win32ss/user/user32/controls/edit.c
Modified: trunk/reactos/win32ss/user/user32/controls/edit.c URL: http://svn.reactos.org/svn/reactos/trunk/reactos/win32ss/user/user32/control... ============================================================================== --- trunk/reactos/win32ss/user/user32/controls/edit.c [iso-8859-1] (original) +++ trunk/reactos/win32ss/user/user32/controls/edit.c [iso-8859-1] Mon Dec 19 16:37:44 2016 @@ -2644,7 +2644,7 @@ if (es->buffer_limit < (tl - (e-s))) strl = 0; else - strl = es->buffer_limit - (tl - (e-s)); + strl = min(strl, es->buffer_limit - (tl - (e-s))); }
if (!EDIT_MakeFit(es, tl - (e - s) + strl))