svn commit: trunk/busybox/coreutils

landley at busybox.net landley at busybox.net
Mon Dec 12 06:49:34 UTC 2005


Author: landley
Date: 2005-12-11 22:49:33 -0800 (Sun, 11 Dec 2005)
New Revision: 12841

Log:
printf() arguments shouldn't be passed straight from user supplied data.
(Security thingy.)


Modified:
   trunk/busybox/coreutils/ln.c


Changeset:
Modified: trunk/busybox/coreutils/ln.c
===================================================================
--- trunk/busybox/coreutils/ln.c	2005-12-12 04:28:17 UTC (rev 12840)
+++ trunk/busybox/coreutils/ln.c	2005-12-12 06:49:33 UTC (rev 12841)
@@ -106,7 +106,7 @@
 		}
 
 		if (link_func(*argv, src) != 0) {
-			bb_perror_msg(src);
+			bb_perror_msg("%s", src);
 			status = EXIT_FAILURE;
 		}
 




More information about the busybox-cvs mailing list