git/gitk-git
Johannes Sixt 4e7e3b792e Merge branch 'ah/fix-open-with-stdin'
This addresses CVE-2025-27614, Arbitrary command execution with Gitk:

A Git repository can be crafted in such a way that with some social
engineering a user who has cloned the repository can be tricked into
running any script (e.g., Bourne shell, Perl, Python, ...) supplied by
the attacker by invoking `gitk filename`, where `filename` has a
particular structure. The script is run with the privileges of the user.

Signed-off-by: Johannes Sixt <j6t@kdbg.org>
2025-05-23 17:04:30 -04:00
..
po Merge gitk to pick up emergency build fix 2019-09-17 14:59:18 -07:00
.gitignore
Makefile Merge git://ozlabs.org/~paulus/gitk 2017-01-18 10:27:59 -08:00
gitk Merge branch 'ah/fix-open-with-stdin' 2025-05-23 17:04:30 -04:00