gbranden pushed a commit to branch 1.24.x
in repository groff.
commit 7845666dc6d9699ab372ef71b906a1921cd3d0c5
Author: G. Branden Robinson <[email protected]>
AuthorDate: Sun Sep 27 14:42:15 2026 -0500
[pdfmom]: Fix Savannah #68687.
* src/utils/pdfmom/pdfmom.pl: Pass arguments from command line through
`Clean` subroutine.
(Clean): New subroutinze sanitizes command-line arguments to defeat
command injection vulnerability.
Fixes <https://savannah.gnu.org/bugs/?68687>. Problem appears to date
back to commit f2a501fff5, 2012-08-31, the initial check-in of the
pdfmom command script, which first shipped in groff 1.22.1. Thanks to
Pavol Sloboda for the report and a reproducer.
---
ChangeLog | 15 +++++++++++++++
src/devices/gropdf/pdfmom.pl | 29 ++++++++++++++++++++---------
2 files changed, 35 insertions(+), 9 deletions(-)
diff --git a/ChangeLog b/ChangeLog
index f5ef74ebb..dfc1d1972 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,18 @@
+2026-09-23 Deri James <[email protected]>
+
+ [pdfmom]: Fix Savannah #68687.
+
+ * src/utils/pdfmom/pdfmom.pl: Pass arguments from command line
+ through `Clean` subroutine.
+ (Clean): New subroutinze sanitizes command-line arguments to
+ defeat command injection vulnerability.
+
+ Fixes <https://savannah.gnu.org/bugs/?68687>. Problem appears
+ to date back to commit f2a501fff5, 2012-08-31, the initial
+ check-in of the pdfmom command script, which first shipped in
+ groff 1.22.1. Thanks to Pavol Sloboda for the report and a
+ reproducer.
+
2026-03-15 G. Branden Robinson <[email protected]>
* src/devices/xditview/xditview.c (main): Avoid invalid memory
diff --git a/src/devices/gropdf/pdfmom.pl b/src/devices/gropdf/pdfmom.pl
index 5511b12e2..7504f205f 100644
--- a/src/devices/gropdf/pdfmom.pl
+++ b/src/devices/gropdf/pdfmom.pl
@@ -79,9 +79,20 @@ sub autopsy
return $finding;
}
-while (my $c=shift)
+sub Clean
+{
+ my $c=shift;
+
+ if (defined($c))
+ {
+ $c=~s/'/'\\''/g;
+ }
+
+ return $c;
+}
+
+while (my $c=Clean(shift))
{
- $c=~s/(?<!\\)"/\\"/g;
if (substr($c,0,2) eq '-T')
{
@@ -91,7 +102,7 @@ while (my $c=shift)
}
else
{
- $dev=shift;
+ $dev=Clean(shift);
}
next;
}
@@ -99,12 +110,12 @@ while (my $c=shift)
{
if (length($c) > 2)
{
- $preconv.=" $c";
+ $preconv.=" '$c'";
}
else
{
- $preconv.=" $c";
- $preconv.=shift;
+ $preconv.=" '$c";
+ $preconv.=Clean(shift)."'";
}
next;
}
@@ -149,8 +160,8 @@ while (my $c=shift)
{
if (length($c) > 1)
{
- push(@cmd,"\"$c\"");
- push(@cmd,"'".(shift)."'") if length($c)==2 and
index('dDfFIKLmMnoPrwW',substr($c,-1)) >= 0;
+ push(@cmd,"'$c'");
+ push(@cmd,"'".Clean(shift)."'") if length($c)==2 and
index('dDfFIKLmMnoPrwW',substr($c,-1)) >= 0;
}
else
{
@@ -164,7 +175,7 @@ while (my $c=shift)
{
# Got a filename?
- push(@cmd,"\"$c\"");
+ push(@cmd,"'$c'");
$readstdin=0 if $readstdin == 1;
}
_______________________________________________
groff-commit mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/groff-commit