[pkg-crosswire-devel] Bug#1149895: trixie-pu: package xiphos/4.3.2+dfsg1-1+deb13u1
Bastian Germann
bage at debian.org
Sun Oct 4 00:08:19 BST 2026
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: xiphos at packages.debian.org
Control: affects -1 + src:xiphos
User: release.debian.org at packages.debian.org
Usertags: pu
[ Reason ]
Fix CVE-2026-79079.
[ Impact ]
A local attacker can execute arbitrary code via this vulnerability.
[ Tests ]
Compilation is okay. The software runs as usual.
[ Risks ]
The included patch is from upstream and applies cleanly.
popen() is replaced with a safeer alternative.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
Replace two popen() calls with GLib's g_spawn_async() and g_spawn_sync() to avoid passing arguments through a shell. This prevents filenames or other data containing shell metacharacters from being interpreted as shell commands.
-------------- next part --------------
diff -Nru xiphos-4.3.2+dfsg1/debian/changelog xiphos-4.3.2+dfsg1/debian/changelog
--- xiphos-4.3.2+dfsg1/debian/changelog 2025-04-13 17:42:46.000000000 +0200
+++ xiphos-4.3.2+dfsg1/debian/changelog 2026-10-03 22:05:37.000000000 +0200
@@ -1,3 +1,10 @@
+xiphos (4.3.2+dfsg1-1+deb13u1) trixie; urgency=medium
+
+ * Team upload
+ * Fix CVE-2026-79079 (local arbitrary code execution)
+
+ -- Bastian Germann <bage at debian.org> Sat, 03 Oct 2026 22:05:37 +0200
+
xiphos (4.3.2+dfsg1-1) unstable; urgency=high
* Team upload
diff -Nru xiphos-4.3.2+dfsg1/debian/patches/0002-CVE-2026-79079.patch xiphos-4.3.2+dfsg1/debian/patches/0002-CVE-2026-79079.patch
--- xiphos-4.3.2+dfsg1/debian/patches/0002-CVE-2026-79079.patch 1970-01-01 01:00:00.000000000 +0100
+++ xiphos-4.3.2+dfsg1/debian/patches/0002-CVE-2026-79079.patch 2026-10-03 22:04:39.000000000 +0200
@@ -0,0 +1,182 @@
+Origin: upstream, f96ad3273277e7fb24908b40f3aa1e9efeeb4e85
+From: Luke <owner at lukesgraphics.com>
+Date: Fri, 22 May 2026 12:34:32 -0500
+Subject: Fix shell command safety: replace popen() with g_spawn functions (#1314)
+
+Replace two popen() calls with GLib's g_spawn_async() and g_spawn_sync()
+to avoid passing arguments through a shell. This prevents filenames or
+other data containing shell metacharacters from being interpreted as
+shell commands.
+
+- src/main/url.cc show_separate_image(): use g_spawn_async() with an
+ argument array and G_SPAWN_STDOUT_TO_DEV_NULL | G_SPAWN_STDERR_TO_DEV_NULL
+ flags, matching the original redirect-to-devnull behavior. Report errors
+ via GError.
+
+- src/gtk/menu_popup.c on_rename_perscomm_activate(): use g_spawn_sync()
+ with sed invoked via argument array. Capture stdout and write the result
+ via g_file_set_contents(). Check exit status and GError.
+
+Co-authored-by: Luke <no-reply at lukesgraphics.com>
+---
+ src/gtk/menu_popup.c | 85 +++++++++++++++++++++++++++++++++-----------
+ src/main/url.cc | 32 ++++++-----------
+ 2 files changed, 76 insertions(+), 41 deletions(-)
+
+diff --git a/src/gtk/menu_popup.c b/src/gtk/menu_popup.c
+index 8154063f3..a6c5af930 100644
+--- a/src/gtk/menu_popup.c
++++ b/src/gtk/menu_popup.c
+@@ -1354,7 +1354,6 @@ G_MODULE_EXPORT void on_rename_perscomm_activate(GtkMenuItem *menuitem,
+ const char *conf_old;
+ char *conf_new;
+ char *sworddir, *modsdir;
+- FILE *result;
+
+ // get a new name for the module.
+ info = gui_new_dialog();
+@@ -1415,28 +1414,74 @@ G_MODULE_EXPORT void on_rename_perscomm_activate(GtkMenuItem *menuitem,
+ goto out2;
+ }
+ // manufacture new .conf from old.
+- g_string_printf(workstr,
+- "( cd \"%s\" && sed -e '/^\\[/s|^.*$|[%s]|' -e '/^DataPath=/s|rawfiles/.*$|rawfiles/%s/|' < \"%s\" > \"%s.conf\" ) 2>&1",
+- modsdir, info->text1, conf_new, conf_old,
+- conf_new);
+- if ((result = popen(workstr->str, "r")) == NULL) {
+- g_string_printf(workstr,
++ gchar *conf_path_old = g_strdup_printf("%s/%s", modsdir, conf_old);
++ gchar *conf_path_new = g_strdup_printf("%s/%s.conf", modsdir, conf_new);
++ gchar *sed_old_sec = g_strdup_printf("[%s]", info->text1);
++ gchar *sed_old_path = g_strdup_printf("rawfiles/%s/", conf_new);
++ gchar *sed_expr = g_strdup_printf(
++ "/^\\[/s|^.*$|%s|;/^DataPath=/s|rawfiles/.*$|%s|",
++ sed_old_sec, sed_old_path);
++ gchar *argv[] = {
++ (gchar *)"sed", (gchar *)"-e", sed_expr, conf_path_old, NULL
++ };
++ GError *spawn_error = NULL;
++ gint exit_status = 0;
++ gchar *spawn_stdout = NULL;
++ gchar *spawn_stderr = NULL;
++ gboolean spawn_ok = g_spawn_sync(modsdir, argv, NULL,
++ G_SPAWN_SEARCH_PATH,
++ NULL, NULL, &spawn_stdout, &spawn_stderr, &exit_status, &spawn_error);
++ if (!spawn_ok) {
++ gchar *msg = g_strdup_printf(
+ _("Failed to create new configuration:\n%s"),
+- strerror(errno));
+- gui_generic_warning_modal(workstr->str);
++ spawn_error ? spawn_error->message : "unknown error");
++ gui_generic_warning_modal(msg);
++ g_free(msg);
++ if (spawn_error) g_error_free(spawn_error);
++ g_free(conf_path_old);
++ g_free(conf_path_new);
++ g_free(sed_old_sec);
++ g_free(sed_old_path);
++ g_free(sed_expr);
++ g_free(spawn_stdout);
++ g_free(spawn_stderr);
++ goto out2;
++ }
++ if (exit_status != 0) {
++ gchar *msg = g_strdup_printf(
++ _("Configuration build error:\n\n%s"),
++ spawn_stderr ? spawn_stderr : "(no error output)");
++ gui_generic_warning_modal(msg);
++ g_free(msg);
++ g_free(conf_path_old);
++ g_free(conf_path_new);
++ g_free(sed_old_sec);
++ g_free(sed_old_path);
++ g_free(sed_expr);
++ g_free(spawn_stdout);
++ g_free(spawn_stderr);
++ goto out2;
++ }
++ // Write sed output to the new .conf file.
++ if (!g_file_set_contents(conf_path_new, spawn_stdout ? spawn_stdout : "",
++ spawn_stdout ? strlen(spawn_stdout) : 0, NULL)) {
++ gui_generic_warning_modal("Failed to write new configuration file.");
++ g_free(conf_path_old);
++ g_free(conf_path_new);
++ g_free(sed_old_sec);
++ g_free(sed_old_path);
++ g_free(sed_expr);
++ g_free(spawn_stdout);
++ g_free(spawn_stderr);
+ goto out2;
+- } else {
+- gchar output[258];
+- if (fgets(output, 256, result) != NULL) {
+- g_string_truncate(workstr, 0);
+- g_string_append(workstr,
+- _("Configuration build error:\n\n"));
+- g_string_append(workstr, output);
+- gui_generic_warning_modal(workstr->str);
+- goto out2; // necessary? advisable?
+- }
+- pclose(result);
+ }
++ g_free(conf_path_old);
++ g_free(conf_path_new);
++ g_free(sed_old_sec);
++ g_free(sed_old_path);
++ g_free(sed_expr);
++ g_free(spawn_stdout);
++ g_free(spawn_stderr);
+
+ // unlink old conf.
+ g_string_printf(workstr, "%s/%s", modsdir, conf_old);
+diff --git a/src/main/url.cc b/src/main/url.cc
+index d7081ce4b..92b997783 100644
+--- a/src/main/url.cc
++++ b/src/main/url.cc
+@@ -172,8 +172,6 @@ static gint show_separate_image(const gchar *filename, gboolean clicked)
+ gui_generic_warning((char *)"Could not display that image");
+ }
+ #else
+- FILE *result;
+- GString *cmd = g_string_new(NULL);
+ int i;
+
+ for (i = 0; display_progs[i]; i++) {
+@@ -186,26 +184,18 @@ static gint show_separate_image(const gchar *filename, gboolean clicked)
+ }
+
+ XI_print(("file = %s\n", filename));
+- g_string_printf(cmd, "%s \"%s\" < /dev/null > /dev/null 2>&1 &",
+- display_progs[i], filename);
+-
+- if ((result = popen(cmd->str, "r")) == NULL) {
+- g_string_printf(cmd,
+- _("Xiphos could not execute %s"),
+- display_progs[i]);
+- gui_generic_warning(cmd->str);
+- } else {
+- gchar output[258];
+- if (fgets(output, 256, result) != NULL) {
+- g_string_truncate(cmd, 0);
+- g_string_append(cmd,
+- _("Viewer error:\n"));
+- g_string_append(cmd, output);
+- gui_generic_warning(cmd->str);
+- }
+- pclose(result);
++ gchar *argv[] = {(gchar *)display_progs[i], (gchar *)filename, NULL};
++ GError *error = NULL;
++ if (!g_spawn_async(NULL, argv, NULL,
++ (GSpawnFlags)(G_SPAWN_SEARCH_PATH | G_SPAWN_STDOUT_TO_DEV_NULL | G_SPAWN_STDERR_TO_DEV_NULL),
++ NULL, NULL, NULL, &error)) {
++ gchar *msg = g_strdup_printf(
++ _("Xiphos could not execute %s: %s"),
++ display_progs[i], error->message);
++ gui_generic_warning(msg);
++ g_free(msg);
++ g_error_free(error);
+ }
+- g_string_free(cmd, TRUE);
+ #endif
+ } else {
+ gui_set_statusbar(filename);
diff -Nru xiphos-4.3.2+dfsg1/debian/patches/series xiphos-4.3.2+dfsg1/debian/patches/series
--- xiphos-4.3.2+dfsg1/debian/patches/series 2025-04-13 17:39:14.000000000 +0200
+++ xiphos-4.3.2+dfsg1/debian/patches/series 2026-10-03 22:05:14.000000000 +0200
@@ -1,2 +1,3 @@
0001-Override-git-version.patch
+0002-CVE-2026-79079.patch
0003-CMake-Don-t-include-win32.patch
More information about the pkg-crosswire-devel
mailing list