gbranden pushed a commit to branch 1.24.x
in repository groff.
commit 6bca15dee3ee04b7529a000fb43cc72649aaee27
Author: G. Branden Robinson <[email protected]>
AuthorDate: Wed Sep 23 12:41:47 2026 -0500
[grohtml]: Fix Savannah #68688 (2/2).
* src/preproc/html/pre-html.cpp (imageList::createImage): Fix command
injection vulnerability by rejecting shell-significant syntax
characters in raster image file names.
Fixes <https://savannah.gnu.org/bugs/?68688> (2/2). Problem appears
to date back to commit a0fae9edb7, 2001-01-07, the initial check-in of
the pre-grohtml preprocessor, which first shipped in groff 1.17.
Thanks to Pavol Sloboda for the report and a reproducer.
---
ChangeLog | 12 ++++++++++++
src/preproc/html/pre-html.cpp | 11 +++++++++++
2 files changed, 23 insertions(+)
diff --git a/ChangeLog b/ChangeLog
index 81d3e7e2a..97adaba6f 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,15 @@
+2026-09-23 G. Branden Robinson <[email protected]>
+
+ * src/preproc/html/pre-html.cpp (imageList::createImage): Fix
+ command injection vulnerability by rejecting shell-significant
+ syntax characters in raster image file names.
+
+ Fixes <https://savannah.gnu.org/bugs/?68688> (2/2). Problem
+ appears to date back to commit a0fae9edb7, 2001-01-07, the
+ initial check-in of the pre-grohtml preprocessor, which first
+ shipped in groff 1.17. Thanks to Pavol Sloboda for the report
+ and a reproducer.
+
2026-09-23 G. Branden Robinson <[email protected]>
* src/roff/troff/input.cpp (do_suppress): Reject `\O5` output
diff --git a/src/preproc/html/pre-html.cpp b/src/preproc/html/pre-html.cpp
index 7b58903d8..03b77f889 100644
--- a/src/preproc/html/pre-html.cpp
+++ b/src/preproc/html/pre-html.cpp
@@ -1049,6 +1049,17 @@ void imageList::createImage(imageItem *i)
+ max(i->Y1, i->Y2) * image_res / postscriptRes
+ 1 + IMAGE_BORDER_PIXELS;
if (createPage(i->pageNo) == 0) {
+ for (const char *p = i->imageName; *p != '\0'; p++) {
+ if (strchr(";&|*?~<>^()[]{}'$`\"\\#", *p != 0 /* nullptr */)) {
+ char q = '\'';
+ if ('\'' == *p)
+ q = '\"';
+ fprintf(stderr, "%s: fatal error: unsafe shell character"
+ " %c%c%c in raster image file name", q, *p, q);
+ fflush(stderr);
+ exit(EXIT_FAILURE);
+ }
+ }
const char *s = make_string("pamcut%s %d %d %d %d < %s "
"| pnmcrop%s " PNMTOOLS_QUIET
"| pnmtopng%s " PNMTOOLS_QUIET " %s"
_______________________________________________
groff-commit mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/groff-commit