[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

git-core 1: for lenny

Hi, please have git-core version 1: migrate to lenny, it
contains a security fix.

 git-core (1: unstable; urgency=high

   * debian/diff/0005-gitweb-do-not-run-git-diff-that-is-Porcelain.diff:
     new; fix possible gitweb vulnerability: calling "git diff": Jakub
     says that legacy-style URI to view two blob differences are never
     generated since 1.4.3.  This codepath runs "git diff" Porcelain from
     the gitweb, which is a no-no.  It can trigger diff.external command
     that is specified in the configuration file of the repository being

Regards, Gerrit.

Reply to: