Comment 16 for bug 27767

Revision history for this message
In , Martin Schulze (joey-infodrom) wrote : Re: Bug#345238: Shell command injection in delegate code (via file names)

Daniel Kobras wrote:
> > Gnah. You are correct. I'm extending the list of forbidden characters
> > by $().
>
> Upstream has reverted the blacklist and instead went for an improved
> version of the symlink fix I added to ImageMagick in unstable. The patch
> is more involved, but also more robust and doesn't impose limits on
> allowed filenames. If you're interested I can extract the changes from
> upstream SVN.

I've sen your patch and decided against it since it is quite intrusive.
The blacklist approach should be sufficient for the updates in our stable
releases.

Regards,

 Joey

--
The MS-DOS filesystem is nice for removable media. -- H. Peter Anvin

Please always Cc to me when replying to me on the lists.