Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Sanitize process name for GUI notification helper
As it turns out, the process name field /proc/PID/stat can contain arbitrary characters. This is a problem, because we call a notification helper, usually notify-send, using system(). Aggressively strip all non-alphanumeric characters to fix a shell code injection vulnerability. Users who do not use GUI notifications (-n or -N) are not affected.
- Loading branch information