On 2017-06-02 09:21, Chris Lamb wrote:
> It's the "same" patch but I also needed to backport split.[ch]. Some
> of the run_cmd callsites were also different in the 1.7 version so it's
> not identical.

Just to be sure, we talk about the same patch...
I meant the one I added Tue, 30 May 2017 to the bug report:
https://bugs.debian.org/cgi-bin/bugreport.cgi?att=1;bug=863671;filename=fix-command-injection-vulnerability;msg=14
It also contains split.[ch] and changed run_cmd calls.
Are there more differences?

Reply via email to