You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SystemTimeToVariantTime发生缓冲区溢出,求排查(附日期转换函数代码)

Fixing Buffer Overflow in SystemTimeToVariantTime

Let’s break down what’s causing that buffer overflow and fix your code step by step:

Key Issues in Your Original Code

  • Mismatched Format Specifiers: Every member of SYSTEMTIME is a WORD (an alias for unsigned short), but you’re using %d (the format specifier for 4-byte int) with sscanf_s. When the function tries to write a full int value into a 2-byte WORD variable, it overruns the SYSTEMTIME structure’s memory. This corruption triggers the buffer overflow when SystemTimeToVariantTime tries to read the damaged data.
  • Risky Wide-to-Narrow Conversion: Using ConvertWstringToCharStar introduces unnecessary complexity—if this function doesn’t allocate memory correctly or returns a pointer to temporary data, you could end up parsing garbage values that worsen the overflow.
  • No Error Checking: You aren’t verifying if sscanf_s successfully parsed all date fields, so invalid input could lead to partial writes that corrupt the SYSTEMTIME structure.

Fixed Code Implementation

Here’s a revised, safer version of your function:

#include <wchar.h>
#include <stdexcept>

void ConvertDateIntoSystemFormat(const std::wstring& dateModified, DATE& date) {
    // Initialize SYSTEMTIME to zero with C++ initializer list (cleaner than memset)
    SYSTEMTIME systemTime = {0};

    // Use swscanf_s to handle wide strings directly—no need for conversion
    int parsedFieldCount = swscanf_s(
        dateModified.c_str(),
        L"%hu-%hu-%huT%hu:%hu:%hu.%huZ",
        &systemTime.wYear,
        &systemTime.wMonth,
        &systemTime.wDay,
        &systemTime.wHour,
        &systemTime.wMinute,
        &systemTime.wSecond,
        &systemTime.wMilliseconds
    );

    // Ensure all 7 date/time fields were parsed correctly
    if (parsedFieldCount != 7) {
        throw std::invalid_argument("Input doesn't match ISO 8601 format (YYYY-MM-DDTHH:MM:SS.sssZ)");
    }

    // Validate the conversion to DATE type
    if (!SystemTimeToVariantTime(&systemTime, &date)) {
        throw std::runtime_error("Failed to convert system time to DATE variant");
    }
}

What Changed & Why

  1. Switched to swscanf_s: This wide-character scan function works directly with std::wstring (via c_str()), eliminating the need for risky wide-to-narrow string conversion.
  2. Corrected Format Specifiers: %hu is the proper format for unsigned short (aka WORD), so we no longer write beyond the bounds of each SYSTEMTIME member.
  3. Safer Initialization: Using SYSTEMTIME systemTime = {0}; is more idiomatic C++ and ensures all structure members start at zero without relying on memset.
  4. Added Error Checking: We verify that all date fields are parsed, and that the final conversion to DATE succeeds. This catches invalid input before it causes memory issues.
  5. Const Reference Parameter: Changing dateModified to a const std::wstring& avoids unnecessary string copies and guarantees we don’t modify the input.

Bonus: Optional Validation

For extra robustness, you can add checks for valid date values (e.g., months 1-12, days matching the month) before calling SystemTimeToVariantTime—this prevents invalid SYSTEMTIME values from causing unexpected behavior.

内容的提问来源于stack exchange,提问作者beasone

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:13:16