131 lines
4.9 KiB
Diff
131 lines
4.9 KiB
Diff
commit 5581ba196d826a984fbfaf792b7d58535f9911ce
|
|
Author: Gary E. Miller <gem@rellim.com>
|
|
Date: Wed Jul 1 17:55:57 2026 -0700
|
|
|
|
clients/gpsprof.py.in: Quote double quotes in title.
|
|
|
|
Someone could use the double quote to break out of the
|
|
string and add gnuplot commnds.
|
|
|
|
For issue 404.
|
|
Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
|
|
|
|
diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
|
|
index 5c18f50ff..261e72665 100644
|
|
--- a/clients/gpsprof.py.in
|
|
+++ b/clients/gpsprof.py.in
|
|
@@ -198,6 +198,10 @@ class plotter(object):
|
|
if 'subtype' in self.device:
|
|
desc += "\\n%s" % self.device['subtype']
|
|
|
|
+ # escape ", and \n, for gnuplot, to not break strings
|
|
+ desc = desc.replace('"', '\\042')
|
|
+ desc = desc.replace('\n', '')
|
|
+
|
|
return desc
|
|
|
|
def collect(self, verb, log_fp=None):
|
|
@@ -1262,10 +1266,10 @@ if __name__ == '__main__':
|
|
# Ship the plot to standard output
|
|
if not options.title:
|
|
options.title = plot.whatami()
|
|
- # escape " for gnuplot
|
|
- options.title = options.title.replace('"', '\\"')
|
|
if options.subtitle:
|
|
options.title += '\\n' + options.subtitle
|
|
+ # escape " for gnuplot, to not break strings
|
|
+ options.title = options.title.replace('"', '\\042')
|
|
term_opts = ""
|
|
truecolor_terms = ['png', 'sixelgd', 'wxt']
|
|
if options.terminal in truecolor_terms:
|
|
|
|
commit 1a6bb7bcbdf58aa940132e630870af061dc88537
|
|
Author: Gary E. Miller <gem@rellim.com>
|
|
Date: Tue Jul 7 13:41:54 2026 -0700
|
|
|
|
clients/gpsprof.py.in: Quote back ticks in title.
|
|
|
|
Someone could use the back tick to break out of the string and add
|
|
gnuplot commnds.
|
|
|
|
For issue 404.
|
|
Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
|
|
|
|
diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
|
|
index 261e72665..202214769 100644
|
|
--- a/clients/gpsprof.py.in
|
|
+++ b/clients/gpsprof.py.in
|
|
@@ -198,8 +198,9 @@ class plotter(object):
|
|
if 'subtype' in self.device:
|
|
desc += "\\n%s" % self.device['subtype']
|
|
|
|
- # escape ", and \n, for gnuplot, to not break strings
|
|
+ # escape ", `, and \n, for gnuplot, to not break strings
|
|
desc = desc.replace('"', '\\042')
|
|
+ desc = desc.replace('`', '\\140')
|
|
desc = desc.replace('\n', '')
|
|
|
|
return desc
|
|
@@ -1268,8 +1269,9 @@ if __name__ == '__main__':
|
|
options.title = plot.whatami()
|
|
if options.subtitle:
|
|
options.title += '\\n' + options.subtitle
|
|
- # escape " for gnuplot, to not break strings
|
|
+ # escape ", and`, for gnuplot, to not break strings
|
|
options.title = options.title.replace('"', '\\042')
|
|
+ options.title = options.title.replace('"', '\\140')
|
|
term_opts = ""
|
|
truecolor_terms = ['png', 'sixelgd', 'wxt']
|
|
if options.terminal in truecolor_terms:
|
|
|
|
commit 4c06658e988f4ced1a7a574ce082a22ef625df56
|
|
Author: Gary E. Miller <gem@rellim.com>
|
|
Date: Tue Jul 7 14:23:56 2026 -0700
|
|
|
|
clients/gpsprof.py.in: Quote back ticks in title.
|
|
|
|
Second try. Also quote "terminal".
|
|
|
|
Someone could use the back tick to break out of the string and add
|
|
gnuplot commnds.
|
|
|
|
For issue 404.
|
|
Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
|
|
|
|
diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
|
|
index 202214769..e91367ee3 100644
|
|
--- a/clients/gpsprof.py.in
|
|
+++ b/clients/gpsprof.py.in
|
|
@@ -200,7 +200,7 @@ class plotter(object):
|
|
|
|
# escape ", `, and \n, for gnuplot, to not break strings
|
|
desc = desc.replace('"', '\\042')
|
|
- desc = desc.replace('`', '\\140')
|
|
+ desc = desc.replace("\x60", '\\140')
|
|
desc = desc.replace('\n', '')
|
|
|
|
return desc
|
|
@@ -1271,13 +1271,19 @@ if __name__ == '__main__':
|
|
options.title += '\\n' + options.subtitle
|
|
# escape ", and`, for gnuplot, to not break strings
|
|
options.title = options.title.replace('"', '\\042')
|
|
- options.title = options.title.replace('"', '\\140')
|
|
+ options.title = options.title.replace("\x60", '\\140')
|
|
term_opts = ""
|
|
truecolor_terms = ['png', 'sixelgd', 'wxt']
|
|
if options.terminal in truecolor_terms:
|
|
term_opts = 'truecolor'
|
|
- sys.stdout.write("set terminal %s size 800,950 %s\n"
|
|
- "set termoption enhanced\n"
|
|
+
|
|
+ # escape ", `, and \n, for gnuplot, to not break strings
|
|
+ options.terminal = options.terminal.replace('"', '\\042')
|
|
+ options.terminal = options.terminal.replace("\x60", '\\140')
|
|
+ options.terminal = options.terminal.replace('\n', '')
|
|
+
|
|
+ sys.stdout.write('set terminal "%s" size 800,950 %s\n'
|
|
+ 'set termoption enhanced\n'
|
|
% (options.terminal, term_opts))
|
|
# double quotes on title so \n is parsed by gnuplot
|
|
sys.stdout.write('set title noenhanced "%s\\n\\n"\n' % options.title)
|