MFC r1.59:
Plug two potential (root-only, local) information leaks. buf is not initialized before use and returned integrally instead of up to size.
Submitted by: Ilja van Sprundel <ilja -at- netric.org>
Reviewed by: secteam
Approved by: re (kensmith)