ImageMagick/CVE-2020-29599-2.patch
2021-01-12 17:00:23 +08:00

23 lines
763 B
Diff

From 2eead004825d31e8f49022f0bc4ca0d3457b0bb1 Mon Sep 17 00:00:00 2001
From: Cristy <urban-warrior@imagemagick.org>
Date: Wed, 20 Nov 2019 07:20:50 -0500
Subject: [PATCH] Santize "'" from SHOW and WIN delegates
---
magick/delegate.c | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/magick/delegate.c b/magick/delegate.c
index 4fec87fc6..32beeb15e 100644
--- a/magick/delegate.c
+++ b/magick/delegate.c
@@ -521,7 +521,7 @@ static char *SanitizeDelegateString(const char *source)
static char
whitelist[] =
"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789 "
- "$-_.+!*'(),{}|\\^~[]`\"><#%/?:@&=";
+ "$-_.+!*;(),{}|\\^~[]`\"><#%/?:@&=";
sanitize_source=AcquireString(source);
p=sanitize_source;