Re: [PATCH] Check for embedded nul in url_pct_decode().

"Kevin J. McCarthy" <[email protected]>
Newsgroups gmane.mail.mutt.devel
Message-ID <aeWgQxC_BvExp5CP@qinghai>
On Sun, Apr 19, 2026 at 08:49:03AM +0200, Alejandro Colomar via Mutt-dev wrote:
>On 2026-04-19T13:52:45+0800, Kevin J. McCarthy wrote:
>> Consider %00 an invalid character in a URL.
>>
>> Thanks to [email protected] for the security report.
>
>This still has the tab/spaces indentation difference with surrounding
>code.  (I don't care; it's just in case you missed it.)
>
>Still, since that's unimportant in stable:
>
>Reviewed-by: Alejandro Colomar <[email protected]>

Pushed to stable.  Merged into master, adjusting for the tab-to-spaces
conversion done in master.

-- 
Kevin J. McCarthy
GPG Fingerprint: 8975 A9B3 3AA3 7910 385C  5308 ADEF 7684 8031 6BDA
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEiXWpszqjeRA4XFMIre92hIAxa9oFAmnloEMACgkQre92hIAx
a9oW0xAApGFUk/9kHrQU7il3EARO7Nft2HyJeI528c1jxGAQpPGbJjeENtH0mHW2
hp2R4aA47TB7XBeEMASsidbnis/nrfgto7L7yyoaf24R/+iovyzePE15oRR2ZYyO
jPphVQJWtdtVodBZXyRFh3K/6FwJco3kM+2ziF+eFoMjSbAs4rKfNEtRAMGu7KFF
SGQF6y+r0BpRhIBmyakSmowQWgqAQJZLJbXzVbwbxfjioEULIxReV06L7zYu69Sl
HtWhPMp7uq25jDkM0IJGzGwojuAGUCyzEsKO1p4Sxf0MTFtM+OGYAW9UUIVu8R4c
yQ/wZ2QjWrvUF8+wfUlni99g+WkoBAW37XERIsleUJtpr4zCQQ/9+KwdqAT9TVfX
UN5lfOHafqAoMMGgTZAZaYxCxniyl+NBb1GODKJgVfVwMfd/Wj6wDp0J0O9KpKxx
wsGSPWFW7U7fMOTEYPxyXdH5T8xrZiWESKKMvVH+2UUNTnpyTVtDMKZWRCK7Ti1x
CQGg83ntaT5hqeNyN0ks3XjtWy92/ntSCwAODUMuS+2NGxpnHxQCbi2ct5Ps1/n3
WwUKKGHoFZcc0Zpv0RC/51mn85jbrTf5398wavs5EbynJL0HoiPMqaIC9gJLUX2Q
vA6MQBc4xsO/y865U8ogZESSJ7oOg8WdhoZXQQZrx9l52WCiFZA=
=RNxa
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.