From: carrerasdarren-cell
<[email protected]>
The TARGET field of a Link line should use the same syntax as a Zone
name or LINK-NAME. Check it before dolink can interpret it as a
pathname outside the output directory.
* NEWS: Mention this.
* zic.c (inlink): Validate LF_TARGET with namecheck.
---
NEWS | 6 ++++++
zic.c | 2 ++
2 files changed, 8 insertions(+)
diff --git a/NEWS b/NEWS
index 3696856b..63af4098 100644
--- a/NEWS
+++ b/NEWS
@@ -6,6 +6,12 @@ Unreleased, experimental changes
Colombia’s 1992-05-02 spring forward was at 00:00, not 24:00.
+ Changes to code
+
+ zic now rejects Link targets that are absolute or contain ‘.’ or
+ ‘..’ components. Previously, crafted input could cause zic to
+ link to a file outside its output directory.
+
Release 2026c - 2026-07-08 10:23:58 -0700
diff --git a/zic.c b/zic.c
index d5e521d6..424dcf07 100644
--- a/zic.c
+++ b/zic.c
@@ -2419,6 +2419,8 @@ inlink(char **fields, int nfields)
error(N_("blank TARGET field on Link line"));
return;
}
+ if (! namecheck(fields[LF_TARGET]))
+ return;
if (! namecheck(fields[LF_LINKNAME]))
return;
l.l_filenum = filenum;
--
2.53.0