Opened 3 weeks ago
Closed 8 days ago
#6021 closed enhancement (fixed)
flit_core-4.1.0 (Python module)
| Reported by: | Bruce Dubbs | Owned by: | lfs-book |
|---|---|---|---|
| Priority: | normal | Milestone: | 13.2 |
| Component: | Book | Version: | git |
| Severity: | normal | Keywords: | |
| Cc: |
Description
New minor version.
Change History (4)
comment:1 by , 8 days ago
| Summary: | flit_core-4.1.0(Python module) → flit_core-4.1.0 (Python module) |
|---|
comment:2 by , 8 days ago
Version 1.24.2 released 2026-09-28
- src/preproc/html/pre-html.cpp (imageList::createImage): Fix
command injection vulnerability by rejecting shell-significant
syntax characters in raster image file names.
- Problem appears to date back to commit a0fae9edb7, 2001-01-07, the initial check-in of the pre-grohtml preprocessor, which first shipped in groff 1.17.
- src/roff/troff/input.cpp (do_suppress): Reject
\O5output suppression escape sequence if it contains shell-unsafe characters in the file name portion of its argument, to advise user of limitation of pre-grohtml(1) preprocessor.- While blindly passing shell-unsafe characters via the
\O5escape sequence is not _itself_ an avenue for command injection, the only _consumer_ of such escape sequences is the pre-grohtml preprocessor (which is vulnerable), so performing strict input validation here makes sense.
- While blindly passing shell-unsafe characters via the
- src/utils/pdfmom/pdfmom.pl: Pass arguments from command line
through
Cleansubroutine. (Clean): New subroutinze sanitizes command-line arguments to defeat command injection vulnerability.- Problem appears to date back to commit f2a501fff5, 2012-08-31, the initial check-in of the pdfmom command script, which first shipped in groff 1.22.1.
- src/devices/xditview/xditview.c (main): Avoid invalid memory
access by checking that
argcis greater than 1 before trying to accessargv[1].
comment:3 by , 8 days ago
- Noteworthy changes in release 1.15 (2026-09-20) [stable]
Bug fixes
gzip no longer can mistakenly remove the wrong file if some other process simultaneously renames a gzip destination's ancestor. [bug present since the beginning]
gzip -d no longer rejects PKZIP signatures, local header, and data descriptors. These can appear in well-formed streamed zip files. [bug present since the beginning]
gzip diagnostics now quote file names containing unusual characters. [bug present since the beginning]
A use of uninitialized memory on some malformed inputs has been fixed. [bug present since the beginning]
A buffer overflow has been fixed when decompressing an .lzh file after decompressing a .Z file. [bug present since the beginning]
When decompressing an .lzh file, the output is no longer corrupted when an internal bit buffer is not properly cleared. [bug present since the beginning]
When decompressing an .lzh file after another .lzh file, the output is no longer corrupted by the previous file's decoding table. [bug present since the beginning]
gzip --synchronous no longer fails to synchronize unreadable parent directories on platforms like GNU/Linux that have O_PATH, or to synchronize any parent directories on platforms like FreeBSD that have O_SEARCH but not O_PATH. [bug introduced in gzip-1.7]
On old-fashioned or limited platforms lacking mktemp, gzexe, zdiff and znew no longer have a race when creating a temporary file. [bug present since the beginning]
Changes in behavior
gzip no longer insists on the "C" locale; instead, it follows the typical practice of using the locale specified by the environment. This change, which is needed for file name quoting, can affect the format of floating-point numbers output by gzip's -l and -v options. Diagnostics are still in English, though.
gzip -l now reports "-Inf%" instead of "0.0%" for the infinite compression ratio of an empty file.
znew's -P option is now ignored, with a warning. It was present only to improve performance, and its implementation had too many bugs to be worth supporting.
Platforms no longer supported
The following platforms (or earlier) are no longer supported because their old multibyte libraries do not work well enough: FreeBSD 4.11 (2005), HP-UX 11.00 (1997), Minix 3.1.8 (2010), MS-Windows 8.1 (2013) via mingw without UCRT.

Version 4.1