ab2c23ac0279b262bbc6ecd601d1da77daefe67d max Fri Sep 25 02:48:37 2026 -0700 htmlTextStripTags and htmlTextStripJavascriptCssAndTags allocated no room for the terminating NUL, so a label without tags got garbage bytes, e.g. in filter tooltips, refs #37617 diff --git src/lib/htmshell.c src/lib/htmshell.c index 654327dc323..23a8c740a52 100644 --- src/lib/htmshell.c +++ src/lib/htmshell.c @@ -166,56 +166,56 @@ } } } void htmlTextOut(char *s) /* Print out string, if necessary replacing > with > and the like */ { htmTextOut(stdout, s); } char *htmlTextStripTags(char *s) /* Returns a cloned string with all html tags stripped out */ { if (s == NULL) return NULL; -char *scrubbed = needMem(strlen(s)); +char *scrubbed = needMem(strlen(s) + 1); char *from=s; char *to=scrubbed; while (*from!='\0') { if (*from == '<') { from++; while (*from!='\0' && *from != '>') from++; if (*from == '\0') // The last open tag was never closed! break; from++; } else *to++ = *from++; } return scrubbed; } char *htmlTextStripJavascriptCssAndTags(char *s) /* Returns a cloned string with all inline javascript, css, and html tags stripped out */ { if (s == NULL) return NULL; -char *scrubbed = needMem(strlen(s)); +char *scrubbed = needMem(strlen(s) + 1); char *from=s; char *to=scrubbed; while (*from!='\0') { if (startsWithNoCase("<script", from)) { from++; while (*from!='\0' && !startsWithNoCase("</script>", from)) from++; if (*from == '\0') // The last open tag was never closed! break; from += strlen("</script>"); *to++ = ' '; } else if (startsWithNoCase("<style", from))