[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[bug #55557] gropdf can execute arbitrary commands
From: |
Colin Watson |
Subject: |
[bug #55557] gropdf can execute arbitrary commands |
Date: |
Thu, 24 Jan 2019 11:12:38 -0500 (EST) |
User-agent: |
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:64.0) Gecko/20100101 Firefox/64.0 |
Follow-up Comment #2, bug #55557 (project groff):
I think all the approaches involving careful @ARGV mangling are far too
delicate and it's too hard to be certain that they're correct. My preference
would be to avoid <> entirely and use three-argument open, as in the attached
patch.
_______________________________________________________
Reply to this item at:
<https://savannah.gnu.org/bugs/?55557>
_______________________________________________
Message sent via Savannah
https://savannah.gnu.org/