Accepted git-annex 5.20141125+oops-1+deb8u2 (source amd64) into oldstable

Date: Tue, 28 Aug 2018 15:20:26 -0400
Source: git-annex
Binary: git-annex
Architecture: source amd64
Version: 5.20141125+oops-1+deb8u2
Distribution: jessie-security
Urgency: high
Maintainer: Joey Hess <joeyh@debian.org>
Changed-By: Antoine Beaupré <anarcat@debian.org>
 git-annex  - manage files with git, without checking their contents into git
 git-annex (5.20141125+oops-1+deb8u2) jessie-security; urgency=high
   * Non-maintainer upload by the Security Team.
   * Switch to non-native package to properly ship security patches. This
     required bumping the upstream version number but we just reused the
     same tarball.
   * Ship CVE-2017-12976.patch correctly (shipped directly in the tarball)
   * To properly fix CVE-2018-10859, backport annex.verify from 5.20151019:
     * Do verification of checksums of annex objects downloaded from remotes.
     * When annex objects are received into git repositories from other git
       repos, their checksums are verified then too.
     * To get the old, faster, behavior of not verifying checksums, set
       annex.verify=false, or remote.<name>.annex-verify=false.
     * setkey, rekey: These commands also now verify that the provided file
       matches the key, unless annex.verify=false.
     * reinject: Already verified content; this can now be disabled by
       setting annex.verify=false.
   * CVE-2018-10857:
     - Added annex.security.allowed-url-schemes setting, which defaults
       to only allowing http, https, and ftp URLs. Note especially that file:/
       is no longer enabled by default.
     - Removed annex.web-download-command, since its interface does not allow
       supporting annex.security.allowed-url-schemes across redirects.
       If you used this setting, you may want to instead use annex.web-options
       to pass options to curl.
     - git-annex will refuse to download content from the web, to prevent
       accidental exposure of data on private webservers on localhost and the
       LAN. This can be overridden with the
       annex.security.allowed-http-addresses setting.
       (The S3, glacier, and webdav special remotes are still allowed to
       download from the web.)
   * CVE-2018-10857 and CVE-2018-10859:
     - Refuse to download content, that cannot be verified with a hash,
       from encrypted special remotes (for CVE-2018-10859),
       and from all external special remotes (for CVE-2018-10857).
       In particular, URL and WORM keys stored on such remotes won't
       be downloaded. If this affects your files, you can run
       `git-annex migrate` on the affected files, to convert them
       to use a hash.
     - Added annex.security.allow-unverified-downloads, which can override
       the above.
