Org Mode vulnerability CVE-2023-28617 is fixed (2/2)
authorXi Lu <lx@shellcodes.org>
Sat, 18 Feb 2023 10:03:28 +0000 (18:03 +0800)
committerRob Browning <rlb@defaultvalue.org>
Sat, 13 May 2023 20:17:27 +0000 (21:17 +0100)
commit04e6964408e0114fd3d751cbfaa278482640e23b
tree48682ceb112564af014ff91577a50bff1c2d1ade
parentc7d0b4b2488683374a024bf88879d1f7b247e479
Org Mode vulnerability CVE-2023-28617 is fixed (2/2)

https://security-tracker.debian.org/tracker/CVE-2023-28617

This upstream patch (2/2) has been incorporated to fix the problem:

Org Mode command injection vulnerability has been fixed (CVE-2023-28617)

  * lisp/ob-latex.el (org-babel-execute:latex): Fix command injection vulnerability

Link: https://orgmode.org/list/tencent_5C4D5D0DEFDDBBFC66F855703927E60C7706@qq.com
  TINYCHANGE

Origin: https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=8f8ec2ccf3f5ef8f38d68ec84a7e4739c45db485
Bug-Debian: https://bugs.debian.org/1033342

Gbp-Pq: Name 0028-Org-Mode-vulnerability-CVE-2023-28617-is-fixed-2-2.patch
lisp/org/ob-latex.el