SECURITY UPDATE: An executable file with some well-known name like zip,
gzip, and so on can be started from a current directory during some
plugin is opening apropriate file that has a one of the extensions .zip,
.gzip, .rb, and etc. This issue is effective only if the PATH
environment variable has a ./ (dot) as one element in the path list
debian/patches/CVE-2023-4736.patch: avoid starting executable from
a current directory for some plugins