<!DOCTYPE html>
<html class="client-js"><head>
  <meta charset="UTF-8">
  <title>strsafe.h</title>
  <meta name="viewport" content="width=device-width, initial-scale=1.0">
  <script>
    function importScript() { return 1 } // this is to avoid the error from site.js
  </script>
  <script>let articleId = 'Strsafe.h'</script>
  <link rel="canonical" href="https://en.wikipedia.org/wiki/Strsafe.h">
  <link href="../-/mw/ext.cite.ux-enhancements.css" rel="stylesheet" type="text/css">
<link href="../-/mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="../-/mw/skins.minerva.base.reset|skins.minerva.content.styles|ext.cite.style|site.styles|mobile.app.pagestyles.android|mediawiki.page.gallery.styles|mediawiki.skinning.content.parsoid.css" rel="stylesheet" type="text/css">
  <link href="../-/style.css" rel="stylesheet" type="text/css"><link href="../-/content.parsoid.css" rel="stylesheet" type="text/css"><link href="../-/inserted_style.css" rel="stylesheet" type="text/css">
  <script src="../-/script.js"></script><script src="../-/masonry.min.js"></script><script src="../-/article_list_home.js"></script><script src="../-/images_loaded.min.js"></script><script src="../-/node_module/details-element-polyfill/dist/details-element-polyfill.js"></script>
</head>

<body class="mediawiki mw-hide-empty-elt ns-0 ns-subject stable skin-minerva action-view animations">
  <div id="mw-mf-viewport" class="feature-header-v2">
    <div id="mw-mf-page-center">
      <div id="content" class="mw-body">
        <a id="top"></a>
        <div id="bodyContent" class="content mw-parser-output">
          
          <div id="mw-content-text" style="direction: ltr;"><h1 class="section-heading" tabindex="0" aria-haspopup="true" data-section-id="0">
  <span class="mw-headline" id="title_0">strsafe.h</span>
</h1>
<div id="mf-section-0" class="mf-section-0" aria-pressed="true" aria-expanded="true">
  <p><b>strsafe.h</b> is a non-standard C header file provided with the Windows SDK starting with Windows XP Service Pack 2<span class="mw-ref reference" id="cite_ref-MSDN1_1-0"><a href="#cite_note-MSDN1-1" style="counter-reset: mw-Ref 1;"><span class="mw-reflink-text">[1]</span></a></span> that provides safer buffer handling than that which is provided by the standard <a href="C_string_handling" title="C string handling">C string functions</a>, which are widely known to have security issues involving <a href="Buffer_overrun" title="Buffer overrun" class="mw-redirect">buffer overruns</a> when not used correctly.</p>

<p><span>
</span><meta property="mw:PageProp/displaytitle" content="strsafe.h"></p>


</div><details data-level="2" open="">
    <summary class="section-heading"><h2 id="Description">Description</h2></summary>
    
<p>The functions included in strsafe.h replace standard C string handling and I/O functions including <code>printf</code>, <code>strlen</code>, <code>strcpy</code> and <code>strcat</code>.<span class="mw-ref reference" id="cite_ref-Richter1_2-0"><a href="#cite_note-Richter1-2" style="counter-reset: mw-Ref 2;"><span class="mw-reflink-text">[2]</span></a></span> The strsafe functions require the length of the string in either characters or bytes as a parameter and if an operation would exceed the length of the destination buffer, the operation fails and the string is still terminated with a <a href="Null_character" title="Null character">null</a> in its final valid index so that using it in other library functions will not result in undefined behavior.<span class="mw-ref reference" id="cite_ref-MSDN1_1-1"><a href="#cite_note-MSDN1-1" style="counter-reset: mw-Ref 1;"><span class="mw-reflink-text">[1]</span></a></span><span class="mw-ref reference" id="cite_ref-Richter1_2-1"><a href="#cite_note-Richter1-2" style="counter-reset: mw-Ref 2;"><span class="mw-reflink-text">[2]</span></a></span>  Independent security researchers have noted that security issues are still possible with the functions from strsafe.h if they are not passed the correct buffer length.<span class="mw-ref reference" id="cite_ref-Daswani1_3-0"><a href="#cite_note-Daswani1-3" style="counter-reset: mw-Ref 3;"><span class="mw-reflink-text">[3]</span></a></span> The use of this library is recommended by the United States Department of Homeland Security.<span class="mw-ref reference" id="cite_ref-4"><a href="#cite_note-4" style="counter-reset: mw-Ref 4;"><span class="mw-reflink-text">[4]</span></a></span></p>


    
</details><details data-level="2" open="">
    <summary class="section-heading"><h2 id="References">References</h2></summary>
    
<div class="reflist " style=" list-style-type: decimal;">
<div class="mw-references-wrap"><ol class="mw-references references"><li id="cite_note-MSDN1-1"> <span id="mw-reference-text-cite_note-MSDN1-1" class="mw-reference-text"><cite class="citation web cs1"><a href="https://msdn.microsoft.com/en-us/library/windows/desktop/ms647466(v=vs.85).aspx" class="external text external">"About Strsafe.h (Windows)"</a>.</cite></span></li><li id="cite_note-Richter1-2"> <span id="mw-reference-text-cite_note-Richter1-2" class="mw-reference-text"><cite id="CITEREFRichterNasarre" class="citation book cs1">Richter, Jeffrey; Nasarre, Christophe. <i>Windows via C/C++ Fifth Edition</i>. Microsoft Press. pp.<span>&nbsp;</span>11–32. <a href="ISBN_(identifier)" title="ISBN (identifier)" class="mw-redirect">ISBN</a><span>&nbsp;</span><bdi>9780735663770</bdi>.</cite></span></li><li id="cite_note-Daswani1-3"> <span id="mw-reference-text-cite_note-Daswani1-3" class="mw-reference-text"><cite id="CITEREFDaswaniKernKesavan" class="citation book cs1">Daswani, Neil; Kern, Christopher; Kesavan, Anita. <i>Foundations of Security: What Every Programmer Needs To Know</i>. Apress Media LLC. p.<span>&nbsp;</span>121. <a href="ISBN_(identifier)" title="ISBN (identifier)" class="mw-redirect">ISBN</a><span>&nbsp;</span><bdi>9781590597842</bdi>.</cite></span></li><li id="cite_note-4"> <span id="mw-reference-text-cite_note-4" class="mw-reference-text"><cite id="CITEREFPlakosh,_Daniel" class="citation web cs1">Plakosh, Daniel. <a href="https://buildsecurityin.us-cert.gov/articles/knowledge/coding-practices/strsafeh" class="external text external">"Strsafe.h | Build Security In"</a>.</cite></span></li></ol></div></div>


    
</details><details data-level="2" open="">
    <summary class="section-heading"><h2 id="External_links">External links</h2></summary>
    
<ul><li><a href="https://msdn.microsoft.com/en-us/library/windows/desktop/ms647466(v=vs.85).aspx" class="external text external">StrSafe.h documentation on MSDN</a></li></ul>



<p>
<br></p>
<style data-mw-deduplicate="TemplateStyles:r982806391">.mw-parser-output cite.citation{font-style:inherit}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .id-lock-free a,.mw-parser-output .citation .cs1-lock-free a{background:linear-gradient(transparent,transparent),url("//upload.wikimedia.org/wikipedia/commons/6/65/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited a,.mw-parser-output .id-lock-registration a,.mw-parser-output .citation .cs1-lock-limited a,.mw-parser-output .citation .cs1-lock-registration a{background:linear-gradient(transparent,transparent),url("//upload.wikimedia.org/wikipedia/commons/d/d6/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription a,.mw-parser-output .citation .cs1-lock-subscription a{background:linear-gradient(transparent,transparent),url("//upload.wikimedia.org/wikipedia/commons/a/aa/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-subscription,.mw-parser-output .cs1-registration{color:#555}.mw-parser-output .cs1-subscription span,.mw-parser-output .cs1-registration span{border-bottom:1px dotted;cursor:help}.mw-parser-output .cs1-ws-icon a{background:linear-gradient(transparent,transparent),url("//upload.wikimedia.org/wikipedia/commons/4/4c/Wikisource-logo.svg")right 0.1em center/12px no-repeat}.mw-parser-output code.cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;font-size:100%}.mw-parser-output .cs1-visible-error{font-size:100%}.mw-parser-output .cs1-maint{display:none;color:#33aa33;margin-left:0.3em}.mw-parser-output .cs1-subscription,.mw-parser-output .cs1-registration,.mw-parser-output .cs1-format{font-size:95%}.mw-parser-output .cs1-kern-left,.mw-parser-output .cs1-kern-wl-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right,.mw-parser-output .cs1-kern-wl-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}</style>
    
</details><!--htdig_noindex--><div><div style="clear:both; background-image:linear-gradient(180deg, #E8E8E8, white); border-top: dashed 2px #AAAAAA; padding: 0.5em 0.5em 0.5em 0.5em; margin-top: 1em; direction: ltr;">
    This article is issued from <a class="external text" title="Last edited on 2017-03-04" href="https://en.wikipedia.org/wiki/?title=Strsafe.h&amp;oldid=768522558">Wikipedia</a>. The text is licensed under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/">Creative Commons - Attribution - Sharealike</a>. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
        </div>
      </div>
    </div>
  </div>
  <script src="../-/mw/jsConfigVars.js"></script>
  <script src="../-/mw/startup.js"></script>
<script src="../-/mw/jquery.js"></script>
<script src="../-/mw/mediawiki.js"></script>
<script src="../-/mw/site.js"></script>
<script src="../-/mw/ext.cite.ux-enhancements.js"></script>



</body></html>