Subject: [ANNOUNCE] Git v2.14.1, v2.13.5, and others
From: Junio C Hamano
Date: 2017-08-10 18:00:04
The latest maintenance release Git v2.14.1 is now available at the
usual places, together with releases for older maintenance track for
the same issue: v2.7.6, v2.8.6, v2.9.5, v2.10.4, v2.11.3, v2.12.4,
and v2.13.5.

These contain a security fix for CVE-2017-1000117, and are released
in coordination with Subversion and Mercurial that share a similar
issue. CVE-2017-9800 and CVE-2017-1000116 are assigned to these
systems, respectively, for issues similar to it that are now
addressed in their part of this coordinated release.

The tarballs are found at:


The following public repositories all have a copy of these tags:

url = https://kernel.googlesource.com/pub/scm/git/git
url = git://repo.or.cz/alt-git.git
url = https://github.com/gitster/git

A malicious third-party can give a crafted “ssh://…” URL to an
unsuspecting victim, and an attempt to visit the URL

