Index: t3lib/thumbs.php =================================================================== --- t3lib/thumbs.php (revision 6261) +++ t3lib/thumbs.php (working copy) @@ -372,17 +372,16 @@ } /** - * Wrapping the input filename in double-quotes + * Escapes a file name so it can safely be used on the command line. + * + * @param string $inputName filename to safeguard, must not be empty * - * @param string Input filename - * @return string The output wrapped in "" (if there are spaces in the filepath) - * @access private + * @return string $inputName escaped as needed + * + * @access protected */ - function wrapFileName($inputName) { - if (strstr($inputName,' ')) { - $inputName='"'.$inputName.'"'; - } - return $inputName; + function wrapFileName($inputName) { + return escapeshellarg($inputName); } }