-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Try this for a fun time:

$ echo 'format(%*.*d,-1,-1,1)' | m4 | wc
      1       1 2280281

Oops - that was 2 million+ characters that I wasn't expecting!  Patch
coming up later.  I don't think the bug can be exploited to run arbitrary
code, but executing printf without enough arguments is never a good idea.

- --
Don't work too hard, make some time for fun as well!

Eric Blake             [EMAIL PROTECTED]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Cygwin)
Comment: Public key at home.comcast.net/~ericblake/eblake.gpg
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGW6jf84KuGfSFAYARAufLAKCtqr+IiG9e1sD1ljKHnBu+VtJyEACgwdLW
YXoa4eOBfiPmmmXKaX3h6pk=
=VJ89
-----END PGP SIGNATURE-----


_______________________________________________
Bug-m4 mailing list
[email protected]
http://lists.gnu.org/mailman/listinfo/bug-m4

Reply via email to