Debian Patches

Status for org-mode/9.4.0+dfsg-1+deb11u1

Patch Description Author Forwarded Bugs Origin Last update
10-shebang.patch Make lintian happy Sebastien Delafond <seb@debian.org> not-needed
30-local-mk.patch Generate all the doc. including the refcard Sebastien Delafond <seb@debian.org> not-needed
0004-Org-Mode-vulnerability-CVE-2023-28617-is-fixed.patch Fix command injection vulnerability CVE-2023-28617
https://security-tracker.debian.org/tracker/CVE-2023-28617

Trivially backport the following upstream patch like emacs-1:28.2+1-15 did:

* lisp/ob-latex.el: Fix command injection vulnerability

(org-babel-execute:latex):
Replaced the `(shell-command "mv BAR NEWBAR")' with `rename-file'.

TINYCHANGE

The second patch of the series does not appear to needed by Org-mode 9.4.0.
Xi Lu <lx@shellcodes.org> no debian https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=a8006ea580ed74f27f974d60b598143b04ad1741 2023-03-11

All known versions for source package 'org-mode'

Links