Fix htmlfontify.el command injection vulnerability (CVE-2022-48339)
authorXi Lu <lx@shellcodes.org>
Sat, 24 Dec 2022 08:28:54 +0000 (16:28 +0800)
committerRob Browning <rlb@defaultvalue.org>
Sat, 13 May 2023 20:17:27 +0000 (21:17 +0100)
commitdc07c703de273f7b563b6245edeb74effdef6f6c
treeeae9656e778de1486e485495debfd7d5fe37718b
parent68c3fb93286be490d2ad78096180817815e63730
Fix htmlfontify.el command injection vulnerability (CVE-2022-48339)

This upstream patch has been incorporated to fix the problem:

  Fix htmlfontify.el command injection vulnerability.

  * lisp/htmlfontify.el (hfy-text-p): Fix command injection
  vulnerability.  (Bug#60295)

Origin: upstream, commit 807d2d5b3a7cd1d0e3f7dd24de22770f54f5ae16
Bug: https://debbugs.gnu.org/60295
Bug-Debian: https://bugs.debian.org/1031730
Forwarded: not-needed

Gbp-Pq: Name 0020-Fix-htmlfontify.el-command-injection-vulnerability-C.patch
lisp/htmlfontify.el