Skip to content
  • Marco Martin's avatar
    Make sure device paths are quoted · 9db872df
    Marco Martin authored
    in the case a vfat removable device has $() or `` in its label,
    such as $(touch foo) the quoted command may get executed,
    leaving an attack vector. Use KMacroExpander::expandMacrosShellQuote
    to make sure everything is quoted and not interpreted as a command
    
    BUG:389815
    9db872df