Browse Source
* maint-2.19: Git 2.19.6 Git 2.18.5 Git 2.17.6 unpack_trees(): start with a fresh lstat cache run-command: invalidate lstat cache after a command finished checkout: fix bug that makes checkout follow symlinks in leading pathmaint
Johannes Schindelin
4 years ago
12 changed files with 216 additions and 4 deletions
@ -0,0 +1,16 @@
@@ -0,0 +1,16 @@
|
||||
Git v2.17.6 Release Notes |
||||
========================= |
||||
|
||||
This release addresses the security issues CVE-2021-21300. |
||||
|
||||
Fixes since v2.17.5 |
||||
------------------- |
||||
|
||||
* CVE-2021-21300: |
||||
On case-insensitive file systems with support for symbolic links, |
||||
if Git is configured globally to apply delay-capable clean/smudge |
||||
filters (such as Git LFS), Git could be fooled into running |
||||
remote code during a clone. |
||||
|
||||
Credit for finding and fixing this vulnerability goes to Matheus |
||||
Tavares, helped by Johannes Schindelin. |
@ -0,0 +1,6 @@
@@ -0,0 +1,6 @@
|
||||
Git v2.18.5 Release Notes |
||||
========================= |
||||
|
||||
This release merges up the fixes that appear in v2.17.6 to address |
||||
the security issue CVE-2021-21300; see the release notes for that |
||||
version for details. |
@ -0,0 +1,6 @@
@@ -0,0 +1,6 @@
|
||||
Git v2.19.6 Release Notes |
||||
========================= |
||||
|
||||
This release merges up the fixes that appear in v2.17.6 and |
||||
v2.18.5 to address the security issue CVE-2021-21300; see the |
||||
release notes for these versions for details. |
Loading…
Reference in new issue