cvsimport: shell-quote variable used in backticks
We run `git rev-parse` though the shell, and quote its argument only with single-quotes. This prevents most metacharacters from being a problem, but misses the obvious case when $name itself has single-quotes in it. We can fix this by applying the usual shell-quoting formula. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Jeff King committed
Sep 11, 2017 at 10:24 UTC
5b4efea666951efe0770f8d5a301f8917015315f
1 file changed
+1
git-cvsimport.perl
+1
@@ -642,6 +642,7 @@ sub is_sha1 {
642
643
sub get_headref ($) {
644
my $name = shift;
645
+ $name =~ s/'/'\\''/;
646
my $r = `git rev-parse --verify '$name' 2>/dev/null`;
647
return undef unless $? == 0;
648
chomp $r;