bug-gnustep
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[bug #34490] -[NSWorkspace open*] native system integration


From: julian
Subject: [bug #34490] -[NSWorkspace open*] native system integration
Date: Sat, 22 Oct 2011 21:50:51 +0000
User-agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/534.51.22 (KHTML, like Gecko) Version/5.1.1 Safari/534.51.22

Follow-up Comment #13, bug #34490 (project gnustep):

>regarding system(), I think the main problem is format string vulnerability

well i am not sure this is a real problem, also validating the string
shouldn't be hard 

but i've updated the patch to use NSTask

btw. if the code you talked about is in GSGhostscriptImageRep, it seems the
code to locate the executables is redundant with the GNUstep NSTask extension
[NSTask+launchPathForTool:]

(file #24187)
    _______________________________________________________

Additional Item Attachment:

File name: open_exp4.txt                  Size:2 KB


    _______________________________________________________

Reply to this item at:

  <http://savannah.gnu.org/bugs/?34490>

_______________________________________________
  Nachricht geschickt von/durch Savannah
  http://savannah.gnu.org/




reply via email to

[Prev in Thread] Current Thread [Next in Thread]