Compare commits

...
Sign in to create a new pull request.

1 commit

Author SHA1 Message Date
Leigh Scott
5cd2cc88c6 Add patch 2026-05-19 21:31:01 +01:00
2 changed files with 68 additions and 1 deletions

View file

@ -0,0 +1,63 @@
From 50052eaa91c3c750c51c245799e3747495feeece Mon Sep 17 00:00:00 2001
From: Victor Kareh <vkareh@redhat.com>
Date: Thu, 14 May 2026 21:56:38 -0400
Subject: [PATCH] ev-application: Quote user-supplied strings in ev_spawn
command line
When spawning a new xreader instance for cross-document links, the
destination and search parameters from the document were interpolated
directly into the command line without shell quoting. Values containing
spaces or special characters could be split into separate arguments by
the shell parser, potentially being interpreted as unintended flags by
the child process.
Apply shell quoting to page label, named destination, and search string
values before appending them to the command line.
---
shell/ev-application.c | 20 +++++++++++++-------
1 file changed, 13 insertions(+), 7 deletions(-)
diff --git a/shell/ev-application.c b/shell/ev-application.c
index a430f9e0..148cfaf8 100644
--- a/shell/ev-application.c
+++ b/shell/ev-application.c
@@ -235,18 +235,22 @@ ev_spawn (const char *uri,
/* Page label or index */
if (dest) {
switch (ev_link_dest_get_dest_type (dest)) {
- case EV_LINK_DEST_TYPE_PAGE_LABEL:
- g_string_append_printf (cmd, " --page-label=%s",
- ev_link_dest_get_page_label (dest));
+ case EV_LINK_DEST_TYPE_PAGE_LABEL: {
+ gchar *quoted = g_shell_quote (ev_link_dest_get_page_label (dest));
+ g_string_append_printf (cmd, " --page-label=%s", quoted);
+ g_free (quoted);
break;
+ }
case EV_LINK_DEST_TYPE_PAGE:
g_string_append_printf (cmd, " --page-index=%d",
ev_link_dest_get_page (dest) + 1);
break;
- case EV_LINK_DEST_TYPE_NAMED:
- g_string_append_printf (cmd, " --named-dest=%s",
- ev_link_dest_get_named_dest (dest));
+ case EV_LINK_DEST_TYPE_NAMED: {
+ gchar *quoted = g_shell_quote (ev_link_dest_get_named_dest (dest));
+ g_string_append_printf (cmd, " --named-dest=%s", quoted);
+ g_free (quoted);
break;
+ }
default:
break;
}
@@ -254,7 +258,9 @@ ev_spawn (const char *uri,
/* Find string */
if (search_string) {
- g_string_append_printf (cmd, " --find=%s", search_string);
+ gchar *quoted = g_shell_quote (search_string);
+ g_string_append_printf (cmd, " --find=%s", quoted);
+ g_free (quoted);
}
/* Mode */

View file

@ -3,13 +3,14 @@
Name: xreader
Version: 4.2.6
Release: 1%{?dist}
Release: 2%{?dist}
Summary: Simple document viewer
# Automatically converted from old format: GPLv2+ - review is highly recommended.
License: GPL-2.0-or-later
URL: https://github.com/linuxmint/%{name}
Source0: %{url}/archive/%{version}/%{name}-%{version}.tar.gz
Patch0: %{url}/commit/50052eaa91c3c750c51c245799e3747495feeece.patch
ExcludeArch: %{ix86}
@ -169,6 +170,9 @@ This package adds configuration to use %{name} as a thumbnailer.
%doc %{_datadir}/doc/%{name}*
%changelog
* Tue May 19 2026 Leigh Scott <leigh123linux@gmail.com> - 4.2.6-2
- Add patch
* Mon May 26 2025 Leigh Scott <leigh123linux@gmail.com> - 4.2.6-1
- Update to 4.2.6
- Disable epub support, it's broken