Org Mode vulnerability CVE-2023-28617 is fixed (2/2)
authorXi Lu <lx@shellcodes.org>
Sat, 18 Feb 2023 10:03:28 +0000 (18:03 +0800)
committerRob Browning <rlb@defaultvalue.org>
Fri, 31 Mar 2023 18:21:11 +0000 (13:21 -0500)
commit023ac1eff558f6fb387fea1629b084c8929de18d
treee0b8bfb59466792d86415a7acf18f06d32bcbe66
parent320ab831aad7b66605e3778abe51a29cc377fb46
Org Mode vulnerability CVE-2023-28617 is fixed (2/2)

https://security-tracker.debian.org/tracker/CVE-2023-28617

This upstream patch (2/2) has been incorporated to fix the problem:

Org Mode command injection vulnerability has been fixed (CVE-2023-28617)

  * lisp/ob-latex.el (org-babel-execute:latex): Fix command injection vulnerability

Link: https://orgmode.org/list/tencent_5C4D5D0DEFDDBBFC66F855703927E60C7706@qq.com
  TINYCHANGE

Origin: https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=8f8ec2ccf3f5ef8f38d68ec84a7e4739c45db485
Bug-Debian: https://bugs.debian.org/1033342
lisp/org/ob-latex.el