box: use vsnprintf() to prevent buffer overflow