public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Miroslav Lichvar <mlichvar@redhat.com>
To: git-commits@fedoraproject.org
Subject: [rpms/gpsd] f43: fix command injection in gpsprof (CVE-2026-58459)
Date: Mon, 13 Jul 2026 13:15:12 GMT	[thread overview]
Message-ID: <178394851263.1.7560889088442941342.rpms-gpsd-83ca7f3c608d@fedoraproject.org> (raw)

A new commit has been pushed.

Repo   : rpms/gpsd
Branch : f43
Commit : 83ca7f3c608d416ed076c3e52e3856f5cb2986ef
Author : Miroslav Lichvar <mlichvar@redhat.com>
Date   : 2026-07-13T15:10:03+02:00
Stats  : +132/-0 in 2 file(s)
URL    : https://src.fedoraproject.org/rpms/gpsd/c/83ca7f3c608d416ed076c3e52e3856f5cb2986ef?branch=f43

Log:
fix command injection in gpsprof (CVE-2026-58459)

---
diff --git a/gpsd-cve-2026-58459.patch b/gpsd-cve-2026-58459.patch
new file mode 100644
index 0000000..8e10713
--- /dev/null
+++ b/gpsd-cve-2026-58459.patch
@@ -0,0 +1,130 @@
+commit 5581ba196d826a984fbfaf792b7d58535f9911ce
+Author: Gary E. Miller <gem@rellim.com>
+Date:   Wed Jul 1 17:55:57 2026 -0700
+
+    clients/gpsprof.py.in: Quote double quotes in title.
+    
+    Someone could use the double quote to break out of the
+    string and add gnuplot commnds.
+    
+    For issue 404.
+    Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
+
+diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
+index 5c18f50ff..261e72665 100644
+--- a/clients/gpsprof.py.in
++++ b/clients/gpsprof.py.in
+@@ -198,6 +198,10 @@ class plotter(object):
+         if 'subtype' in self.device:
+             desc += "\\n%s" % self.device['subtype']
+ 
++        # escape ", and \n, for gnuplot, to not break strings
++        desc = desc.replace('"', '\\042')
++        desc = desc.replace('\n', '')
++
+         return desc
+ 
+     def collect(self, verb, log_fp=None):
+@@ -1262,10 +1266,10 @@ if __name__ == '__main__':
+         # Ship the plot to standard output
+         if not options.title:
+             options.title = plot.whatami()
+-            # escape " for gnuplot
+-            options.title = options.title.replace('"', '\\"')
+         if options.subtitle:
+             options.title += '\\n' + options.subtitle
++        # escape " for gnuplot, to not break strings
++        options.title = options.title.replace('"', '\\042')
+         term_opts = ""
+         truecolor_terms = ['png', 'sixelgd', 'wxt']
+         if options.terminal in truecolor_terms:
+
+commit 1a6bb7bcbdf58aa940132e630870af061dc88537
+Author: Gary E. Miller <gem@rellim.com>
+Date:   Tue Jul 7 13:41:54 2026 -0700
+
+    clients/gpsprof.py.in: Quote back ticks in title.
+    
+    Someone could use the back tick to break out of the string and add
+    gnuplot commnds.
+    
+    For issue 404.
+    Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
+
+diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
+index 261e72665..202214769 100644
+--- a/clients/gpsprof.py.in
++++ b/clients/gpsprof.py.in
+@@ -198,8 +198,9 @@ class plotter(object):
+         if 'subtype' in self.device:
+             desc += "\\n%s" % self.device['subtype']
+ 
+-        # escape ", and \n, for gnuplot, to not break strings
++        # escape ", `, and \n, for gnuplot, to not break strings
+         desc = desc.replace('"', '\\042')
++        desc = desc.replace('`', '\\140')
+         desc = desc.replace('\n', '')
+ 
+         return desc
+@@ -1268,8 +1269,9 @@ if __name__ == '__main__':
+             options.title = plot.whatami()
+         if options.subtitle:
+             options.title += '\\n' + options.subtitle
+-        # escape " for gnuplot, to not break strings
++        # escape ",  and`, for gnuplot, to not break strings
+         options.title = options.title.replace('"', '\\042')
++        options.title = options.title.replace('"', '\\140')
+         term_opts = ""
+         truecolor_terms = ['png', 'sixelgd', 'wxt']
+         if options.terminal in truecolor_terms:
+
+commit 4c06658e988f4ced1a7a574ce082a22ef625df56
+Author: Gary E. Miller <gem@rellim.com>
+Date:   Tue Jul 7 14:23:56 2026 -0700
+
+    clients/gpsprof.py.in: Quote back ticks in title.
+    
+    Second try.  Also quote "terminal".
+    
+    Someone could use the back tick to break out of the string and add
+    gnuplot commnds.
+    
+    For issue 404.
+    Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
+
+diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
+index 202214769..e91367ee3 100644
+--- a/clients/gpsprof.py.in
++++ b/clients/gpsprof.py.in
+@@ -200,7 +200,7 @@ class plotter(object):
+ 
+         # escape ", `, and \n, for gnuplot, to not break strings
+         desc = desc.replace('"', '\\042')
+-        desc = desc.replace('`', '\\140')
++        desc = desc.replace("\x60", '\\140')
+         desc = desc.replace('\n', '')
+ 
+         return desc
+@@ -1271,13 +1271,19 @@ if __name__ == '__main__':
+             options.title += '\\n' + options.subtitle
+         # escape ",  and`, for gnuplot, to not break strings
+         options.title = options.title.replace('"', '\\042')
+-        options.title = options.title.replace('"', '\\140')
++        options.title = options.title.replace("\x60", '\\140')
+         term_opts = ""
+         truecolor_terms = ['png', 'sixelgd', 'wxt']
+         if options.terminal in truecolor_terms:
+             term_opts = 'truecolor'
+-        sys.stdout.write("set terminal %s size 800,950 %s\n"
+-                         "set termoption enhanced\n"
++
++        # escape ", `, and \n, for gnuplot, to not break strings
++        options.terminal = options.terminal.replace('"', '\\042')
++        options.terminal = options.terminal.replace("\x60", '\\140')
++        options.terminal = options.terminal.replace('\n', '')
++
++        sys.stdout.write('set terminal "%s" size 800,950 %s\n'
++                         'set termoption enhanced\n'
+                          % (options.terminal, term_opts))
+         # double quotes on title so \n is parsed by gnuplot
+         sys.stdout.write('set title noenhanced "%s\\n\\n"\n' % options.title)

diff --git a/gpsd.spec b/gpsd.spec
index 194161c..d5c5bb6 100644
--- a/gpsd.spec
+++ b/gpsd.spec
@@ -38,6 +38,8 @@ Patch1:         gpsd-apistatus.patch
 Patch2:         gpsd-cve-2025-67268.patch
 # Fix integer underflow in handling of Navcom packets
 Patch3:         gpsd-cve-2025-67269.patch
+# Fix command injection in gpsprof
+Patch4:         gpsd-cve-2026-58459.patch
 
 BuildRequires:  gcc
 BuildRequires:  dbus-devel

                 reply	other threads:[~2026-07-13 13:15 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=178394851263.1.7560889088442941342.rpms-gpsd-83ca7f3c608d@fedoraproject.org \
    --to=mlichvar@redhat.com \
    --cc=git-commits@fedoraproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox