[xml/sgml-pkgs] Bug#516916: dblatex: fails when directory name contain spaces

Vincent Lefevre vincent at vinc17.net
Sun Jun 18 01:53:51 UTC 2017


Control: tags -1 security
Control: severity -1 important

On 2009-03-01 12:58:30 +0100, Mike Hommey wrote:
> This has to do with apparently the CLI commands (xmllint and xsltproc)
> not converting path names to proper URIs. If you replace spaces with
> %20 in the file names on the command line, it works as expected.

Actually it's much uglier than that. There seems some internal breakage
so that in fact, xmllint tries to read the wrong file, as I've noted in
the upstream bug: from the current directory instead of the expected
directory. This implies possible user information leakage.

-- 
Vincent Lefèvre <vincent at vinc17.net> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)



More information about the debian-xml-sgml-pkgs mailing list