Change logs for git source package in Nile V2.0
-
git (1:2.43.0-ok4) nile; urgency=medium
* SECURITY UPDATE: Facilitation of arbitrary code execution -
debian/patches/CVE-2024-32002.patch: submodule paths must not
contains symlinks in builtin/submodule--helper.c. - CVE-2024-
32002 * SECURITY UPDATE: Arbitrary code execution -
debian/patches/CVE-2024-32004.patch: detect dubious ownership of
local repositories in path.c, setup.c, setup.h. - CVE-2024-32004
* SECURITY UPDATE: Overwrite of possible malicious hardlink -
debian/patches/CVE-2024-32020.patch: refuse clones of unsafe
repositories in builtin/clonse.c, t0033-safe-directory.sh. - CVE-
2024-32020 * SECURITY UPDATE: Unauthenticated attacker to place a
repository on their target's local system that contains symlinks
- debian/patches/CVE-2024-32021.patch: abort when hardlinked source
and target file differ in builtin/clone.c - CVE-2024-32021
* SECURITY UPDATE: Arbitrary code execution - debian/patches/CVE-
2024-32465.patch: disable lazy-fetching by default in
builtin/upload-pack.c, promisor-remote.c - CVE-2024-32465
-- liubo01 <email address hidden> Mon, 04 Nov 2024 16:27:31 +0800
-
git (1:2.43.0-ok3) nile; urgency=medium
* rebuild
-- liyang <email address hidden> Wed, 03 Jul 2024 18:49:46 +0800
-
git (1:2.43.0-ok2) nile; urgency=medium
* update changelog.
-- liubo01 <email address hidden> Sat, 15 Jun 2024 09:35:20 +0800
-
git (1:2.25.1-ok9) yangtze; urgency=high
* indira-bupt CVE-2023-22490 安全更新:Git存在安全漏洞,攻击者利用该漏洞导致数据泄露.
* indira-bupt CVE-2023-23946 安全更新:Git存在安全漏洞,攻击者利用该漏洞可以访问存储在Web根文件夹之外的文件和目录.
-- zgy_is <email address hidden> Tue, 28 Feb 2023 11:20:17 +0800