Skip to content

Commit fc464bc

Browse files
fix: V-001 security vulnerability
Automated security fix generated by Orbis Security AI
1 parent db0ee44 commit fc464bc

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

Programs/_freeze_module.c

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -126,7 +126,7 @@ compile_and_marshal(const char *name, const char *text)
126126
if (filename == NULL) {
127127
return PyErr_NoMemory();
128128
}
129-
sprintf(filename, "<frozen %s>", name);
129+
snprintf(filename, strlen(name) + 10, "<frozen %s>", name);
130130
PyObject *code = Py_CompileStringExFlags(text, filename,
131131
Py_file_input, NULL, 0);
132132
free(filename);
@@ -153,7 +153,7 @@ get_varname(const char *name, const char *prefix)
153153
if (varname == NULL) {
154154
return NULL;
155155
}
156-
(void)strcpy(varname, prefix);
156+
memcpy(varname, prefix, n);
157157
for (size_t i = 0; name[i] != '\0'; i++) {
158158
if (name[i] == '.') {
159159
varname[n++] = '_';

0 commit comments

Comments
 (0)