Buffer overflow in sion_generic_paropen
sion_generic_paropen
allocates a buffer lprefix
of fixed length SION_FILENAME_LENGTH
and then uses strcpy
to copy the user-provided argument fname
into lprefix
without checking the length of fname
.