Prevent people from reading the first line of arbitrary files through
bugreport.cgi.
my %pkgsrc = %{getpkgsrc()};
my $ref = $param{'bug'} || quit("No bug number");
+$ref =~ /(\d+)/ or quit("Invalid bug number");
+$ref = $1;
my $msg = $param{'msg'} || "";
my $att = $param{'att'};
my $boring = ($param{'boring'} || 'no') eq 'yes';
package name, closes: #93433. [Colin]
* Remove support for -fixed address from receive, since nothing else
supports it. [Colin]
+ * Prevent people from reading the first line of arbitrary files through
+ bugreport.cgi, thanks to Max <rusmir@tula.net>. [Colin]
* Fix a few typos, closes: #146745, #152751.
* Various other things, not worth mentioning here.