Blame SOURCES/0008-Fix-CVE-2017-8386.patch

fdd391
From 654dbd112ab7cbe0a162afaab645a971da62d433 Mon Sep 17 00:00:00 2001
fdd391
From: Petr Stodulka <pstodulk@redhat.com>
fdd391
Date: Wed, 17 May 2017 11:37:01 +0200
fdd391
Subject: [PATCH] Fix CVE-2017-8386
fdd391
fdd391
See the commit 3ec804490 in upstream repository for more info.
fdd391
---
fdd391
 shell.c | 2 +-
fdd391
 1 file changed, 1 insertion(+), 1 deletion(-)
fdd391
fdd391
diff --git a/shell.c b/shell.c
fdd391
index 1429870..72ed0fa 100644
fdd391
--- a/shell.c
fdd391
+++ b/shell.c
fdd391
@@ -13,7 +13,7 @@ static int do_generic_cmd(const char *me, char *arg)
fdd391
 	const char *my_argv[4];
fdd391
 
fdd391
 	setup_path();
fdd391
-	if (!arg || !(arg = sq_dequote(arg)))
fdd391
+	if (!arg || !(arg = sq_dequote(arg)) || *arg == '-')
fdd391
 		die("bad argument");
fdd391
 	if (prefixcmp(me, "git-"))
fdd391
 		die("bad command");
fdd391
-- 
fdd391
2.9.4
fdd391