-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 According to Eric Blake on 11/22/2007 7:39 AM: > $ m4 -F /nosuch/%x </dev/null > m4: /nosuch/0: No such file or directory > > If that doesn't scare you, consider a file name that contains %n. This > security hole has been present since M4 1.3.
Fortunately, it was fixed on the master branch in Aug 2006 (commit c38df). - -- Don't work too hard, make some time for fun as well! Eric Blake [EMAIL PROTECTED] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (Cygwin) Comment: Public key at home.comcast.net/~ericblake/eblake.gpg Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFHRZeV84KuGfSFAYARAue8AJ9B7wS1BpNwUc+hjbYVIyZF0BucYQCgiGHS ptujXpFAdz673jyByUMiOjo= =dHYT -----END PGP SIGNATURE----- _______________________________________________ M4-patches mailing list [email protected] http://lists.gnu.org/mailman/listinfo/m4-patches
