![gitster@pobox.com](/assets/img/avatar_default.png)
10 changed files with 122 additions and 7 deletions
@ -0,0 +1,16 @@
@@ -0,0 +1,16 @@
|
||||
Git v2.17.4 Release Notes |
||||
========================= |
||||
|
||||
This release is to address the security issue: CVE-2020-5260 |
||||
|
||||
Fixes since v2.17.3 |
||||
------------------- |
||||
|
||||
* With a crafted URL that contains a newline in it, the credential |
||||
helper machinery can be fooled to give credential information for |
||||
a wrong host. The attack has been made impossible by forbidding |
||||
a newline character in any value passed via the credential |
||||
protocol. |
||||
|
||||
Credit for finding the vulnerability goes to Felix Wilhelm of Google |
||||
Project Zero. |
@ -0,0 +1,5 @@
@@ -0,0 +1,5 @@
|
||||
Git v2.18.3 Release Notes |
||||
========================= |
||||
|
||||
This release merges the security fix that appears in v2.17.4; see |
||||
the release notes for that version for details. |
@ -1 +1 @@
@@ -1 +1 @@
|
||||
Documentation/RelNotes/2.18.2.txt |
||||
Documentation/RelNotes/2.18.3.txt |
Loading…
Reference in new issue