Re: Help wanted evaluating claimed security vulnerability in groff

Sebastien Peterson-Boudreau <[email protected]> Fri, 29 May 2026 14:14:18 -0300
Newsgroups gmane.comp.printing.groff.general
Message-ID <CAGPRubTaYQUR35MwZ=L9_u_NTRivVcK_z-3pEURgk8T4F5Wp5A@mail.gmail.com>
Branden put it well. While there is some possibility of this being
used to trick some clueless user into executing some commands they
otherwise wouldn't have executed, said user would need to be clueless
enough to copy-paste commands they don't understand into the shell
prompt, in which case you could just get them to execute the commands
directly instead of going through a DESC file.

Maybe this report is useful if you want to play a practical joke on
your friends (who do trust you enough to blindly compile a groff
document you send them with a custom DESC file) -- I'll be using this
information that way.