groff
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Groff] Re: Bug#107459: pic can be forced to run commands in safe mo


From: Werner LEMBERG
Subject: Re: [Groff] Re: Bug#107459: pic can be forced to run commands in safe mode
Date: Sat, 04 Aug 2001 09:29:11 +0200 (CEST)

> > pic can be forced to execute commands (sh X..X) when running in safe
> > mode (-S). It can be exploited trough lpd when groff/pic is run in
> > print filters, and arbitrary commands with id of lpd can be run.
> 
> Are you aware of this problem?

Yes.  The very reason that it hasn't been fixed yet is that I need a
free implementation of snprintf() -- additionally I was on vacation.
Should be fixed in the next few weeks.


    Werner

reply via email to

[Prev in Thread] Current Thread [Next in Thread]