Ensure that escape_display_name() can't overrun a buffer.
[mmh] / sbr / mts.c
index 556d740..b529d15 100644 (file)
--- a/sbr/mts.c
+++ b/sbr/mts.c
@@ -397,7 +397,7 @@ getuserinfo (void)
 
     fullname[sizeof(fullname) - 1] = '\0';
 
-    escape_display_name(fullname);
+    escape_display_name(fullname, sizeof(fullname));
 
     localmbox[0] = '\0';