File CVE-2024-32487.patch of Package less.34274

From 007521ac3c95bc76e3d59c6dbfe75d06c8075c33 Mon Sep 17 00:00:00 2001
From: Mark Nudelman <markn@greenwoodsoftware.com>
Date: Thu, 11 Apr 2024 17:49:48 -0700
Subject: [PATCH] Fix bug when viewing a file whose name contains a newline.

---
 filename.c | 31 +++++++++++++++++++++++++------
 1 file changed, 25 insertions(+), 6 deletions(-)

Index: less-643/filename.c
===================================================================
--- less-643.orig/filename.c
+++ less-643/filename.c
@@ -134,6 +134,15 @@ static int metachar(char c)
 }
 
 /*
+ * Must use quotes rather than escape char for this metachar?
+ */
+static int must_quote(char c)
+{
+	/* {{ Maybe the set of must_quote chars should be configurable? }} */
+	return (c == '\n'); 
+}
+
+/*
  * Insert a backslash before each metacharacter in a string.
  */
 public char * shell_quote(char *s)
@@ -164,6 +173,9 @@ public char * shell_quote(char *s)
 				 * doesn't support escape chars.  Use quotes.
 				 */
 				use_quotes = 1;
+			} else if (must_quote(*p))
+			{
+				len += 3; /* open quote + char + close quote */
 			} else
 			{
 				/*
@@ -193,15 +205,22 @@ public char * shell_quote(char *s)
 	{
 		while (*s != '\0')
 		{
-			if (metachar(*s))
+			if (!metachar(*s))
 			{
-				/*
-				 * Add the escape char.
-				 */
+				*p++ = *s++;
+			} else if (must_quote(*s))
+			{
+				/* Surround the char with quotes. */
+				*p++ = openquote;
+				*p++ = *s++;
+				*p++ = closequote;
+			} else
+			{
+				/* Insert an escape char before the char. */
 				strcpy(p, esc);
 				p += esclen;
+				*p++ = *s++;
 			}
-			*p++ = *s++;
 		}
 		*p = '\0';
 	}
openSUSE Build Service is sponsored by