use-s-format-to-print-untrusted-string.patch 492 B

1234567891011121314151617
  1. Upstream-Author: Reuben Thomas <rrt@sc3d.org>
  2. Date: Mon Sep 20 14:24:01 2010 +0000
  3. Upstream-Commit: b05926f28f3cab0ef77101f89be154329dcb8dea
  4. Description:
  5. Use '%s' format to print untrusted string.
  6. --- a/src/softmagic.c
  7. +++ b/src/softmagic.c
  8. @@ -1592,7 +1592,7 @@
  9. if (offset == 0)
  10. return 0;
  11. if ((ms->flags & (MAGIC_MIME|MAGIC_APPLE)) == 0 &&
  12. - file_printf(ms, m->desc) == -1)
  13. + file_printf(ms, "%s", m->desc) == -1)
  14. return -1;
  15. if (nbytes < offset)
  16. return 0;