The shown C code has a buffer overflow vulnerability:
#include <string.h>
#include <stdlib.h>
char *add_domain_name(char *source) {
const size_t size = 1024;
char *dest = malloc(size+1);
strncpy(dest, source, size);
strncat(dest, "@example.com", size);
return dest;
}
`strncat` takes as a third parameter the maximum length of the appended string. strncat(dest, "@example.com", size - strlen(dest));
would be correct.