gbranden pushed a commit to branch 1.24.x
in repository groff.

commit abc3478bbb7996ba4608ebcb0ac8a421fd6c93db
Author: G. Branden Robinson <[email protected]>
AuthorDate: Wed Sep 23 12:27:22 2026 -0500

    [troff]: Fix Savannah #68688 (1/2).
    
    * src/roff/troff/input.cpp (do_suppress): Reject `\O5` output
      suppression escape sequence if it contains shell-unsafe characters in
      the file name portion of its argument, to advise user of limitation of
      pre-grohtml(1) preprocessor.
    
    Fixes <https://savannah.gnu.org/bugs/?68688> (1/2).  While blindly
    passing shell-unsafe characters via the `\O5` escape sequence is not
    _itself_ an avenue for command injection, the only _consumer_ of such
    escape sequences is the pre-grohtml preprocessor (which is vulnerable),
    so performing strict input validation here makes sense.
---
 ChangeLog                | 14 ++++++++++++++
 src/roff/troff/input.cpp | 14 ++++++++++++++
 2 files changed, 28 insertions(+)

diff --git a/ChangeLog b/ChangeLog
index dfc1d1972..81d3e7e2a 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,17 @@
+2026-09-23  G. Branden Robinson <[email protected]>
+
+       * src/roff/troff/input.cpp (do_suppress): Reject `\O5` output
+       suppression escape sequence if it contains shell-unsafe
+       characters in the file name portion of its argument, to advise
+       user of limitation of pre-grohtml(1) preprocessor.
+
+       Fixes <https://savannah.gnu.org/bugs/?68688> (1/2).  While
+       blindly passing shell-unsafe characters via the `\O5` escape
+       sequence is not _itself_ an avenue for command injection, the
+       only _consumer_ of such escape sequences is the pre-grohtml
+       preprocessor (which is vulnerable), so performing strict input
+       validation here makes sense.
+
 2026-09-23  Deri James  <[email protected]>
 
        [pdfmom]: Fix Savannah #68687.
diff --git a/src/roff/troff/input.cpp b/src/roff/troff/input.cpp
index bef670fd4..5ebc530b0 100644
--- a/src/roff/troff/input.cpp
+++ b/src/roff/troff/input.cpp
@@ -6995,6 +6995,20 @@ static node *do_suppress(symbol nm) // \O
              " sequence");
        return 0 /* nullptr */;
       }
+      // pre-grohtml runs troff (using the "ps" output device).  It also
+      // has a function called `html_system()` that calls the dreaded
+      // system(3).
+      for (const char *p = s; *p != '\0'; p++) {
+       if (strchr(";&|*?~<>^()[]{}'$`\"\\#", *p) != 0 /* nullptr */) {
+         char q = '\'';
+         if ('\'' == *p)
+           q = '\"';
+         error("rejecting image file name argument"
+               " containing unsafe shell character %1%2%3"
+               " in output suppression escape sequence", q, *p, q);
+         return 0 /* nullptr */;
+       }
+      }
       image_no++;
       if (0 == suppression_level)
        return new suppress_node(symbol(s), position, image_no);

_______________________________________________
groff-commit mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/groff-commit

Reply via email to