On Oct 25, 2011, at 6:29 PM, s...@apache.org wrote:
> 
> +    if (len > maxlen && maxlen > 0)
> +        return APR_ENOMEM;
> +
>     if (!vb) {
> -        dest = dst = apr_pcalloc(p, len + 1);
> +        *result = dst = apr_pcalloc(p, len + 1);

if len == maxlen and == APR_SIZE_MAX then doesn't
the len+1 blow us up?

Reply via email to