On Oct 25, 2011, at 6:29 PM, s...@apache.org wrote: > > + if (len > maxlen && maxlen > 0) > + return APR_ENOMEM; > + > if (!vb) { > - dest = dst = apr_pcalloc(p, len + 1); > + *result = dst = apr_pcalloc(p, len + 1);
if len == maxlen and == APR_SIZE_MAX then doesn't the len+1 blow us up?