pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/editors/emacs29



Module Name:    pkgsrc
Committed By:   wiz
Date:           Sat Sep 12 14:34:57 UTC 2026

Modified Files:
        pkgsrc/editors/emacs29: Makefile distinfo
Added Files:
        pkgsrc/editors/emacs29/patches: patch-lisp_man.el

Log Message:
emacs29: fix CVE-2025-1244

Bump PKGREVISION.

>From Showta Ishizaki in PR 60711.


To generate a diff of this commit:
cvs rdiff -u -r1.48 -r1.49 pkgsrc/editors/emacs29/Makefile
cvs rdiff -u -r1.5 -r1.6 pkgsrc/editors/emacs29/distinfo
cvs rdiff -u -r0 -r1.1 pkgsrc/editors/emacs29/patches/patch-lisp_man.el

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/editors/emacs29/Makefile
diff -u pkgsrc/editors/emacs29/Makefile:1.48 pkgsrc/editors/emacs29/Makefile:1.49
--- pkgsrc/editors/emacs29/Makefile:1.48        Wed Sep  2 19:01:47 2026
+++ pkgsrc/editors/emacs29/Makefile     Sat Sep 12 14:34:56 2026
@@ -1,8 +1,8 @@
-# $NetBSD: Makefile,v 1.48 2026/09/02 19:01:47 wiz Exp $
+# $NetBSD: Makefile,v 1.49 2026/09/12 14:34:56 wiz Exp $
 
 CONFLICTS+=    emacs29-nox11-[0-9]*
 
-PKGREVISION=   30
+PKGREVISION=   31
 
 .include "../../editors/emacs29/Makefile.common"
 

Index: pkgsrc/editors/emacs29/distinfo
diff -u pkgsrc/editors/emacs29/distinfo:1.5 pkgsrc/editors/emacs29/distinfo:1.6
--- pkgsrc/editors/emacs29/distinfo:1.5 Mon Dec 22 19:51:06 2025
+++ pkgsrc/editors/emacs29/distinfo     Sat Sep 12 14:34:56 2026
@@ -1,7 +1,8 @@
-$NetBSD: distinfo,v 1.5 2025/12/22 19:51:06 tron Exp $
+$NetBSD: distinfo,v 1.6 2026/09/12 14:34:56 wiz Exp $
 
 BLAKE2s (emacs-29.4.tar.xz) = dfe3ab5088f59a4c153aaf5e18920d4c81beffdd678d4fa4116abbe49ed41e2f
 SHA512 (emacs-29.4.tar.xz) = 66b38081cb01d2c46ff7beefb45986cc225b4c922c30712ad0d456c6cae5507176ed99418c8f26948c5375c8afde4e4b2507d23ed997dbb5392d12150a121d80
 Size (emacs-29.4.tar.xz) = 52210344 bytes
 SHA1 (patch-Makefile.in) = cb43792c8996c781f382ae102ea771af8f3d3190
+SHA1 (patch-lisp_man.el) = 31f79fdca013bfb725d82877263ca1ebe16505f5
 SHA1 (patch-src_treesit.c) = f58370000074137997b8119ab55f49f2964010bb

Added files:

Index: pkgsrc/editors/emacs29/patches/patch-lisp_man.el
diff -u /dev/null pkgsrc/editors/emacs29/patches/patch-lisp_man.el:1.1
--- /dev/null   Sat Sep 12 14:34:57 2026
+++ pkgsrc/editors/emacs29/patches/patch-lisp_man.el    Sat Sep 12 14:34:57 2026
@@ -0,0 +1,24 @@
+$NetBSD: patch-lisp_man.el,v 1.1 2026/09/12 14:34:57 wiz Exp $
+
+Man-getpage-in-background runs the man command under sh -c, and passes
+whatever Man-translate-references returns straight into it.  A reference
+with no section part is returned unchanged, so "M-x man RET ;id RET" runs
+id.  Fix from upstream commit 820f0793f0 ("Fix man.el shell injection
+vulnerability"), debbugs 66390, landed only in 30.1; this package stays on
+29.4.
+
+--- lisp/man.el.orig
++++ lisp/man.el
+@@ -684,7 +684,11 @@
+       (setq name (match-string 2 ref)
+           section (match-string 1 ref))))
+     (if (string= name "")
+-      ref                             ; Return the reference as is
++        ;; see Bug#66390
++      (mapconcat 'identity
++                   (mapcar #'shell-quote-argument
++                           (split-string ref "\\s-+"))
++                   " ")                 ; Return the reference as is
+       (if Man-downcase-section-letters-flag
+         (setq section (downcase section)))
+       (while slist



Home | Main Index | Thread Index | Old Index