These were all caused by sprintf() appending a null char that was not actually used. Fixes CVE-2021-30498 and CVE-2021-30499.