diff options
-rw-r--r-- | libbb/lineedit.c | 12 |
1 files changed, 12 insertions, 0 deletions
diff --git a/libbb/lineedit.c b/libbb/lineedit.c index c0e35bb21..56e81404e 100644 --- a/libbb/lineedit.c +++ b/libbb/lineedit.c | |||
@@ -645,6 +645,18 @@ static void free_tab_completion_data(void) | |||
645 | 645 | ||
646 | static void add_match(char *matched) | 646 | static void add_match(char *matched) |
647 | { | 647 | { |
648 | unsigned char *p = (unsigned char*)matched; | ||
649 | while (*p) { | ||
650 | /* ESC attack fix: drop any string with control chars */ | ||
651 | if (*p < ' ' | ||
652 | || (!ENABLE_UNICODE_SUPPORT && *p >= 0x7f) | ||
653 | || (ENABLE_UNICODE_SUPPORT && *p == 0x7f) | ||
654 | ) { | ||
655 | free(matched); | ||
656 | return; | ||
657 | } | ||
658 | p++; | ||
659 | } | ||
648 | matches = xrealloc_vector(matches, 4, num_matches); | 660 | matches = xrealloc_vector(matches, 4, num_matches); |
649 | matches[num_matches] = matched; | 661 | matches[num_matches] = matched; |
650 | num_matches++; | 662 | num_matches++; |