You are here: Home » NewsFeeds » Update Git software now (and svn and mercurial)

Update Git software now (and svn and mercurial)

[prev in list] [next in list] [prev in thread] [next in thread]

List: git
Subject: [ANNOUNCE] Git v2.14.1, v2.13.5, and others
From: Junio C Hamano
Date: 2017-08-10 18:00:04
Message-ID: xmqqh8xf482j.fsf () gitster ! mtv ! corp ! google ! com
[Download message RAW]

The latest maintenance release Git v2.14.1 is now available at the
usual places, together with releases for older maintenance track for
the same issue: v2.7.6, v2.8.6, v2.9.5, v2.10.4, v2.11.3, v2.12.4,
and v2.13.5.

These contain a security fix for CVE-2017-1000117, and are released
in coordination with Subversion and Mercurial that share a similar
issue. CVE-2017-9800 and CVE-2017-1000116 are assigned to these
systems, respectively, for issues similar to it that are now
addressed in their part of this coordinated release.

The tarballs are found at:

https://www.kernel.org/pub/software/scm/git/

The following public repositories all have a copy of these tags:

url = https://kernel.googlesource.com/pub/scm/git/git
url = git://repo.or.cz/alt-git.git
url = https://github.com/gitster/git

A malicious third-party can give a crafted “ssh://…” URL to an
unsuspecting victim, and an attempt to visit the URL


 

Original article