gbranden pushed a commit to branch 1.24.x
in repository groff.
commit c0fc6947165cef2cefa1062f95f7eba989540081
Author: G. Branden Robinson <[email protected]>
AuthorDate: Tue Sep 22 22:33:02 2026 -0500
[mm]: Fix Savannah #68689.
* contrib/mm/mmroff.pl: In main loop, drop use of `eval` in favor of a
simpler hash assignment, preventing a shell command injection
vulnerability in mmroff(1) when a malicious input file inserts a
specially crafted comment line into the standard output or error
streams of the first groff(1) pass this command performs.
Problem appears to date back to commit e092fba451, 2000-02-06, the
initial check-in of the "mmroff.pl" script, which first shipped in groff
1.16. Thanks to Pavol Sloboda for the report and a reproducer, and to
Ingo Schwarze for help preparing a fix.
---
contrib/mm/ChangeLog | 15 +++++++++++++++
contrib/mm/mmroff.pl | 2 +-
2 files changed, 16 insertions(+), 1 deletion(-)
diff --git a/contrib/mm/ChangeLog b/contrib/mm/ChangeLog
index 111b918e7..15ac1ea63 100644
--- a/contrib/mm/ChangeLog
+++ b/contrib/mm/ChangeLog
@@ -1,3 +1,18 @@
+2026-09-22 G. Branden Robinson <[email protected]>
+
+ Fix Savannah #68689.
+
+ * mmroff.pl: In main loop, drop use of `eval` in favor of a
+ simpler hash assignment, preventing a shell command injection
+ vulnerability in mmroff(1) when a malicious input file inserts a
+ specially crafted comment line into the standard output or error
+ streams of the first groff(1) pass this command performs.
+
+ Problem appears to date back to commit e092fba451, 2000-02-06,
+ the initial check-in of the "mmroff.pl" script, which first
+ shipped in groff 1.16. Thanks to Pavol Sloboda for the report
+ and a reproducer, and to Ingo Schwarze for help preparing a fix.
+
2026-02-19 G. Branden Robinson <[email protected]>
* tests/LB-mark-format-works.sh: Rename this...
diff --git a/contrib/mm/mmroff.pl b/contrib/mm/mmroff.pl
index d7f593b27..f8b16ee9d 100644
--- a/contrib/mm/mmroff.pl
+++ b/contrib/mm/mmroff.pl
@@ -127,7 +127,7 @@ while(<MACRO>) {
next;
}
if (m#^\.\\" PIC (\w+)\s+(\S+)#) {
- eval "\$cur{'$1'} = '$2'";
+ $cur{"$1"} = '$2';
next;
}
s#\\ \\ $##;
_______________________________________________
groff-commit mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/groff-commit