|
From: | Max Nikulin |
Subject: | bug#66390: `man' allows to inject arbitrary shell code |
Date: | Tue, 10 Oct 2023 17:54:59 +0700 |
User-agent: | Mozilla Thunderbird |
On 09/10/2023 23:30, lux wrote:
Here's my patch and the test cases.
Thank you for your attempt to fix the issue. Unfortunately the proposed patch breaks the following case
M-x man RET -k man RET That is why I wrote that each word should escaped independently. I am unsure if (man "-k man") should be supported as call with argument.
[Prev in Thread] | Current Thread | [Next in Thread] |