julianf...@apache.org wrote on Fri, Apr 26, 2013 at 19:59:09 -0000: > Author: julianfoad > Date: Fri Apr 26 19:59:09 2013 > New Revision: 1476366 > > URL: http://svn.apache.org/r1476366 > Log: > * subversion/svn/props.c > (svn_cl__check_svn_prop_name): Eliminate an unsafe printf format string > by using svn_error_create() instead of svn_error_createf(). >
unsafe printf string == heap underflow == potential segfault == backport candidate? Daniel > Modified: > subversion/trunk/subversion/svn/props.c > > Modified: subversion/trunk/subversion/svn/props.c > URL: > http://svn.apache.org/viewvc/subversion/trunk/subversion/svn/props.c?rev=1476366&r1=1476365&r2=1476366&view=diff > ============================================================================== > --- subversion/trunk/subversion/svn/props.c (original) > +++ subversion/trunk/subversion/svn/props.c Fri Apr 26 19:59:09 2013 > @@ -321,7 +321,7 @@ svn_cl__check_svn_prop_name(const char * > { > case 0: > /* The best alternative isn't good enough */ > - return svn_error_createf( > + return svn_error_create( > SVN_ERR_CLIENT_PROPERTY_NAME, NULL, > wrong_prop_error_message(prop_use, propname, scratch_pool)); > > >