On 2017-06-02 09:21, Chris Lamb wrote: > It's the "same" patch but I also needed to backport split.[ch]. Some > of the run_cmd callsites were also different in the 1.7 version so it's > not identical.
Just to be sure, we talk about the same patch... I meant the one I added Tue, 30 May 2017 to the bug report: https://bugs.debian.org/cgi-bin/bugreport.cgi?att=1;bug=863671;filename=fix-command-injection-vulnerability;msg=14 It also contains split.[ch] and changed run_cmd calls. Are there more differences?