[CVE-2017-9502] url: fix buffer overwrite with file protocol