ab2c23ac0279b262bbc6ecd601d1da77daefe67d
max
Fri Sep 25 02:48:37 2026 -0700
htmlTextStripTags and htmlTextStripJavascriptCssAndTags allocated no room for the terminating NUL, so a label without tags got garbage bytes, e.g. in filter tooltips, refs #37617
diff --git src/lib/htmshell.c src/lib/htmshell.c
index 654327dc323..23a8c740a52 100644
--- src/lib/htmshell.c
+++ src/lib/htmshell.c
@@ -166,56 +166,56 @@
}
}
}
void htmlTextOut(char *s)
/* Print out string, if necessary replacing > with > and the like */
{
htmTextOut(stdout, s);
}
char *htmlTextStripTags(char *s)
/* Returns a cloned string with all html tags stripped out */
{
if (s == NULL)
return NULL;
-char *scrubbed = needMem(strlen(s));
+char *scrubbed = needMem(strlen(s) + 1);
char *from=s;
char *to=scrubbed;
while (*from!='\0')
{
if (*from == '<')
{
from++;
while (*from!='\0' && *from != '>')
from++;
if (*from == '\0') // The last open tag was never closed!
break;
from++;
}
else
*to++ = *from++;
}
return scrubbed;
}
char *htmlTextStripJavascriptCssAndTags(char *s)
/* Returns a cloned string with all inline javascript, css, and html tags stripped out */
{
if (s == NULL)
return NULL;
-char *scrubbed = needMem(strlen(s));
+char *scrubbed = needMem(strlen(s) + 1);
char *from=s;
char *to=scrubbed;
while (*from!='\0')
{
if (startsWithNoCase("");
*to++ = ' ';
}
else if (startsWithNoCase("