Reopened and added duplicity-team to the subscribers. This is not as simple as splitting the command line into parts. As long as you can make the the pathname contain ';', you can insert commands. Given the example you gave last," ;xmessage hello bug;#/test" is a valid filename, so filename validation will not work.
Reopened and added duplicity-team to the subscribers. This is not as simple as splitting the command line into parts. As long as you can make the the pathname contain ';', you can insert commands. Given the example you gave last," ;xmessage hello bug;#/test" is a valid filename, so filename validation will not work.