From: carrerasdarren-cell 
<[email protected]>

The TARGET field of a Link line should use the same syntax as a Zone
name or LINK-NAME.  Check it before dolink can interpret it as a
pathname outside the output directory.

* NEWS: Mention this.
* zic.c (inlink): Validate LF_TARGET with namecheck.
---
 NEWS  | 6 ++++++
 zic.c | 2 ++
 2 files changed, 8 insertions(+)

diff --git a/NEWS b/NEWS
index 3696856b..63af4098 100644
--- a/NEWS
+++ b/NEWS
@@ -6,6 +6,12 @@ Unreleased, experimental changes
 
     Colombia’s 1992-05-02 spring forward was at 00:00, not 24:00.
 
+  Changes to code
+
+    zic now rejects Link targets that are absolute or contain ‘.’ or
+    ‘..’ components.  Previously, crafted input could cause zic to
+    link to a file outside its output directory.
+
 
 Release 2026c - 2026-07-08 10:23:58 -0700
 
diff --git a/zic.c b/zic.c
index d5e521d6..424dcf07 100644
--- a/zic.c
+++ b/zic.c
@@ -2419,6 +2419,8 @@ inlink(char **fields, int nfields)
                error(N_("blank TARGET field on Link line"));
                return;
        }
+       if (! namecheck(fields[LF_TARGET]))
+         return;
        if (! namecheck(fields[LF_LINKNAME]))
          return;
        l.l_filenum = filenum;
-- 
2.53.0

Reply via email to