In addition to the CGI problem I just mentioned, I have also been asked by Red Hat Product Security to forward more reports upstream. However, they are based on a questionable threat model, where attackers can influence the source code being formatted or the execution environment that source-highlight runs in. I can still forward them to this mailing list if you are interested.
Thanks, Florian _______________________________________________ Help-source-highlight mailing list [email protected] https://lists.gnu.org/mailman/listinfo/help-source-highlight
