gbranden pushed a commit to branch 1.24.x
in repository groff.

commit 6bca15dee3ee04b7529a000fb43cc72649aaee27
Author: G. Branden Robinson <[email protected]>
AuthorDate: Wed Sep 23 12:41:47 2026 -0500

    [grohtml]: Fix Savannah #68688 (2/2).
    
    * src/preproc/html/pre-html.cpp (imageList::createImage): Fix command
      injection vulnerability by rejecting shell-significant syntax
      characters in raster image file names.
    
      Fixes <https://savannah.gnu.org/bugs/?68688> (2/2).  Problem appears
      to date back to commit a0fae9edb7, 2001-01-07, the initial check-in of
      the pre-grohtml preprocessor, which first shipped in groff 1.17.
      Thanks to Pavol Sloboda for the report and a reproducer.
---
 ChangeLog                     | 12 ++++++++++++
 src/preproc/html/pre-html.cpp | 11 +++++++++++
 2 files changed, 23 insertions(+)

diff --git a/ChangeLog b/ChangeLog
index 81d3e7e2a..97adaba6f 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,15 @@
+2026-09-23  G. Branden Robinson <[email protected]>
+
+       * src/preproc/html/pre-html.cpp (imageList::createImage): Fix
+       command injection vulnerability by rejecting shell-significant
+       syntax characters in raster image file names.
+
+       Fixes <https://savannah.gnu.org/bugs/?68688> (2/2).  Problem
+       appears to date back to commit a0fae9edb7, 2001-01-07, the
+       initial check-in of the pre-grohtml preprocessor, which first
+       shipped in groff 1.17.  Thanks to Pavol Sloboda for the report
+       and a reproducer.
+
 2026-09-23  G. Branden Robinson <[email protected]>
 
        * src/roff/troff/input.cpp (do_suppress): Reject `\O5` output
diff --git a/src/preproc/html/pre-html.cpp b/src/preproc/html/pre-html.cpp
index 7b58903d8..03b77f889 100644
--- a/src/preproc/html/pre-html.cpp
+++ b/src/preproc/html/pre-html.cpp
@@ -1049,6 +1049,17 @@ void imageList::createImage(imageItem *i)
             + max(i->Y1, i->Y2) * image_res / postscriptRes
             + 1 + IMAGE_BORDER_PIXELS;
     if (createPage(i->pageNo) == 0) {
+      for (const char *p = i->imageName; *p != '\0'; p++) {
+       if (strchr(";&|*?~<>^()[]{}'$`\"\\#", *p != 0 /* nullptr */)) {
+         char q = '\'';
+         if ('\'' == *p)
+           q = '\"';
+         fprintf(stderr, "%s: fatal error: unsafe shell character"
+                 " %c%c%c in raster image file name", q, *p, q);
+         fflush(stderr);
+         exit(EXIT_FAILURE);
+       }
+      }
       const char *s = make_string("pamcut%s %d %d %d %d < %s "
                                  "| pnmcrop%s " PNMTOOLS_QUIET
                                  "| pnmtopng%s " PNMTOOLS_QUIET " %s"

_______________________________________________
groff-commit mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/groff-commit

Reply via email to