commit | 89a62bf2907412cb562d22c875736357e314c8c8 | [log] [tgz] |
---|---|---|
author | Rob Landley <rob@landley.net> | Mon Jun 09 05:51:04 2014 -0500 |
committer | Rob Landley <rob@landley.net> | Mon Jun 09 05:51:04 2014 -0500 |
tree | 0dbb98c25b73f9320c090c7aeceb98ea2fe23fa6 | |
parent | c421b7068c5dd95baa10f9bd97e578d04ba48c70 [diff] |
When locale is enabled, sprintf("%.123s", str) is counting characters, not bytes, so we can't globally enable locale without opening stack/heap smashing vulnerabilities. Make commands individually request setlocale() using TOYFLAGS instead.