Bug#433900: call to shell with unquoted user-supplied filenames

2007-07-20 Thread Zoran Dzelajlija
On Fri, Jul 20, 2007 at 11:38:11AM +0200, Cosimo Alfarano wrote: > > On 20 Jul 2007, at 10:45, Zoran Dzelajlija wrote: > >I can work around this easily by renaming the file ;-), but it > >could be a security issue in other cases so I'm tagging it as > >such. > > I'll upload a new version, 0.44, f

Bug#433900: call to shell with unquoted user-supplied filenames

2007-07-20 Thread Cosimo Alfarano
On 20 Jul 2007, at 10:45, Zoran Dzelajlija wrote: I can work around this easily by renaming the file ;-), but it could be a security issue in other cases so I'm tagging it as such. I'll upload a new version, 0.44, for which concern unstable. If it is fixed I'll try to backport it in stable,

Bug#433900: call to shell with unquoted user-supplied filenames

2007-07-20 Thread Zoran Dzelajlija
Package: gocr Version: 0.41-1 Severity: minor Tags: security --- Please enter the report below this line. --- Hi, gocr is calling a child process with sh -c and expands the argument needlessly. [10:33] ~ => strace -ff -e fork,execve gocr big-in-japan-\(alphaville-cover\).png execve("/usr/bin/go