Commit 211b9e55 authored by Daniel Stenberg's avatar Daniel Stenberg
Browse files

curl_unescape() could make a buffer overflow

parent bc5c4b89
Loading
Loading
Loading
Loading
+2 −2
Original line number Diff line number Diff line
@@ -47,7 +47,7 @@

char *curl_escape(char *string)
{
   int alloc=strlen(string);
   int alloc=strlen(string)+1;
   char *ns = malloc(alloc);
   unsigned char in;
   int newlen = alloc;
@@ -83,7 +83,7 @@ char *curl_escape(char *string)

char *curl_unescape(char *string)
{
   int alloc = strlen(string);
   int alloc = strlen(string)+1;
   char *ns = malloc(alloc);
   unsigned char in;
   int index=0;