Commit 05290a50 authored by Kevin Atkinson's avatar Kevin Atkinson

Untaint results from escapeshellarg.

parent a2486b1c
......@@ -1466,7 +1466,8 @@ sub escapeshellarg($)
my ($str) = @_;
$str =~ s/[^[:alnum:]]/\\$&/g;
return $str;
$str =~ /^(.+)$/; # untaint the result
return $1;
}
# _Always_ make sure that this 1 is at the end of the file...
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment