gbranden pushed a commit to branch 1.24.x
in repository groff.
commit abc3478bbb7996ba4608ebcb0ac8a421fd6c93db
Author: G. Branden Robinson <[email protected]>
AuthorDate: Wed Sep 23 12:27:22 2026 -0500
[troff]: Fix Savannah #68688 (1/2).
* src/roff/troff/input.cpp (do_suppress): Reject `\O5` output
suppression escape sequence if it contains shell-unsafe characters in
the file name portion of its argument, to advise user of limitation of
pre-grohtml(1) preprocessor.
Fixes <https://savannah.gnu.org/bugs/?68688> (1/2). While blindly
passing shell-unsafe characters via the `\O5` escape sequence is not
_itself_ an avenue for command injection, the only _consumer_ of such
escape sequences is the pre-grohtml preprocessor (which is vulnerable),
so performing strict input validation here makes sense.
---
ChangeLog | 14 ++++++++++++++
src/roff/troff/input.cpp | 14 ++++++++++++++
2 files changed, 28 insertions(+)
diff --git a/ChangeLog b/ChangeLog
index dfc1d1972..81d3e7e2a 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,17 @@
+2026-09-23 G. Branden Robinson <[email protected]>
+
+ * src/roff/troff/input.cpp (do_suppress): Reject `\O5` output
+ suppression escape sequence if it contains shell-unsafe
+ characters in the file name portion of its argument, to advise
+ user of limitation of pre-grohtml(1) preprocessor.
+
+ Fixes <https://savannah.gnu.org/bugs/?68688> (1/2). While
+ blindly passing shell-unsafe characters via the `\O5` escape
+ sequence is not _itself_ an avenue for command injection, the
+ only _consumer_ of such escape sequences is the pre-grohtml
+ preprocessor (which is vulnerable), so performing strict input
+ validation here makes sense.
+
2026-09-23 Deri James <[email protected]>
[pdfmom]: Fix Savannah #68687.
diff --git a/src/roff/troff/input.cpp b/src/roff/troff/input.cpp
index bef670fd4..5ebc530b0 100644
--- a/src/roff/troff/input.cpp
+++ b/src/roff/troff/input.cpp
@@ -6995,6 +6995,20 @@ static node *do_suppress(symbol nm) // \O
" sequence");
return 0 /* nullptr */;
}
+ // pre-grohtml runs troff (using the "ps" output device). It also
+ // has a function called `html_system()` that calls the dreaded
+ // system(3).
+ for (const char *p = s; *p != '\0'; p++) {
+ if (strchr(";&|*?~<>^()[]{}'$`\"\\#", *p) != 0 /* nullptr */) {
+ char q = '\'';
+ if ('\'' == *p)
+ q = '\"';
+ error("rejecting image file name argument"
+ " containing unsafe shell character %1%2%3"
+ " in output suppression escape sequence", q, *p, q);
+ return 0 /* nullptr */;
+ }
+ }
image_no++;
if (0 == suppression_level)
return new suppress_node(symbol(s), position, image_no);
_______________________________________________
groff-commit mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/groff-commit