300aad
diff -up a2ps-4.14/lib/output.c.format-security a2ps-4.14/lib/output.c
35dadd
--- a2ps-4.14/lib/output.c.format-security	2007-12-29 01:58:21.000000000 +0000
35dadd
+++ a2ps-4.14/lib/output.c	2014-04-03 18:24:35.259901356 +0100
300aad
@@ -525,7 +525,7 @@ output_file (struct output * out, a2ps_j
300aad
 		     expand_user_string (job, FIRST_FILE (job),
300aad
 					 (const uchar *) "Expand: requirement",
300aad
 					 (const uchar *) token));
300aad
-	output (dest, expansion);
300aad
+	output (dest, "%s", expansion);
300aad
 	continue;
300aad
       }
300aad
 
35dadd
diff -up a2ps-4.14/lib/parseppd.y.format-security a2ps-4.14/lib/parseppd.y
35dadd
--- a2ps-4.14/lib/parseppd.y.format-security	2007-12-29 01:58:21.000000000 +0000
35dadd
+++ a2ps-4.14/lib/parseppd.y	2014-04-03 18:24:35.259901356 +0100
35dadd
@@ -154,7 +154,7 @@ font_clause :
35dadd
 void
35dadd
 yyerror (const char *msg)
35dadd
 {
35dadd
-  error_at_line (1, 0, ppdfilename, ppdlineno, msg);
35dadd
+  error_at_line (1, 0, ppdfilename, ppdlineno, "%s", msg);
35dadd
 }
35dadd
 
35dadd
 /*
35dadd
diff -up a2ps-4.14/lib/psgen.c.format-security a2ps-4.14/lib/psgen.c
35dadd
--- a2ps-4.14/lib/psgen.c.format-security	2014-04-03 18:24:35.241901276 +0100
35dadd
+++ a2ps-4.14/lib/psgen.c	2014-04-03 18:24:35.259901356 +0100
35dadd
@@ -232,7 +232,7 @@ output_marker (a2ps_job * job, const cha
35dadd
     default:
35dadd
       *buf = '\0';
35dadd
       ps_escape_char (job, cp[i], buf);
35dadd
-      output (jdiv, (char *) buf);
35dadd
+      output (jdiv, "%s", (char *) buf);
35dadd
       break;
35dadd
     }
35dadd
   }
35dadd
diff -up a2ps-4.14/src/parsessh.y.format-security a2ps-4.14/src/parsessh.y
35dadd
--- a2ps-4.14/src/parsessh.y.format-security	2014-04-03 18:25:56.011259069 +0100
35dadd
+++ a2ps-4.14/src/parsessh.y	2014-04-03 18:26:04.725297585 +0100
35dadd
@@ -740,7 +740,7 @@ exception_def_opt:
35dadd
 void
35dadd
 yyerror (const char *msg)
35dadd
 {
35dadd
-  error_at_line (1, 0, sshfilename, sshlineno, msg);
35dadd
+  error_at_line (1, 0, sshfilename, sshlineno, "%s", msg);
35dadd
 }
35dadd
 
35dadd
 /*