File tree Expand file tree Collapse file tree 3 files changed +18
-2
lines changed Expand file tree Collapse file tree 3 files changed +18
-2
lines changed Original file line number Diff line number Diff line change 1+ Git v2.14.5 Release Notes
2+ =========================
3+
4+ This release is to address the recently reported CVE-2018-17456.
5+
6+ Fixes since v2.14.4
7+ -------------------
8+
9+ * Submodules' "URL"s come from the untrusted .gitmodules file, but
10+ we blindly gave it to "git clone" to clone submodules when "git
11+ clone --recurse-submodules" was used to clone a project that has
12+ such a submodule. The code has been hardened to reject such
13+ malformed URLs (e.g. one that begins with a dash).
14+
15+ Credit for finding and fixing this vulnerability goes to joernchen
16+ and Jeff King, respectively.
Original file line number Diff line number Diff line change 11#! /bin/sh
22
33GVF=GIT-VERSION-FILE
4- DEF_VER=v2.14.4
4+ DEF_VER=v2.14.5
55
66LF='
77'
Original file line number Diff line number Diff line change 1- Documentation/RelNotes/2.14.4 .txt
1+ Documentation/RelNotes/2.14.5 .txt
You can’t perform that action at this time.
0 commit comments