diff options
| author | Victor Kareh <[email protected]> | 2026-05-14 20:56:31 -0400 |
|---|---|---|
| committer | Victor Kareh <[email protected]> | 2026-05-14 21:15:20 -0400 |
| commit | b989b7922a454ed81f8bb14786a958828513f576 (patch) | |
| tree | 051adf41046df38f9ac6272743670af933b543c9 /libview | |
| parent | 1cf7c928e3d2bcfad548fdb747dff5cbc3d1441f (diff) | |
| download | atril-b989b7922a454ed81f8bb14786a958828513f576.tar.bz2 atril-b989b7922a454ed81f8bb14786a958828513f576.tar.xz | |
ev-application: Quote user-supplied strings in ev_spawn command line
When spawning a new atril instance for cross-document links, the
destination and search parameters from the document were interpolated
directly into the command line without shell quoting. Values containing
spaces or special characters could be split into separate arguments by
the shell parser, potentially being interpreted as unintended flags by
the child process.
Apply shell quoting to page label, named destination, and search string
values before appending them to the command line, consistent with how
other spawn sites in the codebase already handle this.
Diffstat (limited to 'libview')
0 files changed, 0 insertions, 0 deletions
