gbranden pushed a commit to branch 1.24.x
in repository groff.

commit 7845666dc6d9699ab372ef71b906a1921cd3d0c5
Author: G. Branden Robinson <[email protected]>
AuthorDate: Sun Sep 27 14:42:15 2026 -0500

    [pdfmom]: Fix Savannah #68687.
    
    * src/utils/pdfmom/pdfmom.pl: Pass arguments from command line through
      `Clean` subroutine.
    
      (Clean): New subroutinze sanitizes command-line arguments to defeat
      command injection vulnerability.
    
    Fixes <https://savannah.gnu.org/bugs/?68687>.  Problem appears to date
    back to commit f2a501fff5, 2012-08-31, the initial check-in of the
    pdfmom command script, which first shipped in groff 1.22.1.  Thanks to
    Pavol Sloboda for the report and a reproducer.
---
 ChangeLog                    | 15 +++++++++++++++
 src/devices/gropdf/pdfmom.pl | 29 ++++++++++++++++++++---------
 2 files changed, 35 insertions(+), 9 deletions(-)

diff --git a/ChangeLog b/ChangeLog
index f5ef74ebb..dfc1d1972 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,18 @@
+2026-09-23  Deri James  <[email protected]>
+
+       [pdfmom]: Fix Savannah #68687.
+
+       * src/utils/pdfmom/pdfmom.pl: Pass arguments from command line
+       through `Clean` subroutine.
+       (Clean): New subroutinze sanitizes command-line arguments to
+       defeat command injection vulnerability.
+
+       Fixes <https://savannah.gnu.org/bugs/?68687>.  Problem appears
+       to date back to commit f2a501fff5, 2012-08-31, the initial
+       check-in of the pdfmom command script, which first shipped in
+       groff 1.22.1.  Thanks to Pavol Sloboda for the report and a
+       reproducer.
+
 2026-03-15  G. Branden Robinson <[email protected]>
 
        * src/devices/xditview/xditview.c (main): Avoid invalid memory
diff --git a/src/devices/gropdf/pdfmom.pl b/src/devices/gropdf/pdfmom.pl
index 5511b12e2..7504f205f 100644
--- a/src/devices/gropdf/pdfmom.pl
+++ b/src/devices/gropdf/pdfmom.pl
@@ -79,9 +79,20 @@ sub autopsy
     return $finding;
 }
 
-while (my $c=shift)
+sub Clean
+{
+    my $c=shift;
+
+    if (defined($c))
+    {
+        $c=~s/'/'\\''/g;
+    }
+
+    return $c;
+}
+
+while (my $c=Clean(shift))
 {
-    $c=~s/(?<!\\)"/\\"/g;
 
     if (substr($c,0,2) eq '-T')
     {
@@ -91,7 +102,7 @@ while (my $c=shift)
        }
        else
        {
-           $dev=shift;
+           $dev=Clean(shift);
        }
        next;
     }
@@ -99,12 +110,12 @@ while (my $c=shift)
     {
        if (length($c) > 2)
        {
-           $preconv.=" $c";
+           $preconv.=" '$c'";
        }
        else
        {
-           $preconv.=" $c";
-           $preconv.=shift;
+           $preconv.=" '$c";
+           $preconv.=Clean(shift)."'";
        }
        next;
     }
@@ -149,8 +160,8 @@ while (my $c=shift)
     {
        if (length($c) > 1)
        {
-           push(@cmd,"\"$c\"");
-           push(@cmd,"'".(shift)."'") if length($c)==2 and 
index('dDfFIKLmMnoPrwW',substr($c,-1)) >= 0;
+           push(@cmd,"'$c'");
+           push(@cmd,"'".Clean(shift)."'") if length($c)==2 and 
index('dDfFIKLmMnoPrwW',substr($c,-1)) >= 0;
        }
        else
        {
@@ -164,7 +175,7 @@ while (my $c=shift)
     {
        # Got a filename?
 
-       push(@cmd,"\"$c\"");
+       push(@cmd,"'$c'");
        $readstdin=0 if $readstdin == 1;
 
     }

_______________________________________________
groff-commit mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/groff-commit

Reply via email to