git.git
8 years agoMerge git (1:1.7.10.4-1+wheezy6) import into refs/heads/workingbranch
Antoine Beaupré [Mon, 2 Oct 2017 19:47:26 +0000 (20:47 +0100)]
Merge git (1:1.7.10.4-1+wheezy6) import into refs/heads/workingbranch

8 years agogit (1:1.7.10.4-1+wheezy6) wheezy-security; urgency=high
Antoine Beaupré [Mon, 2 Oct 2017 19:47:26 +0000 (20:47 +0100)]
git (1:1.7.10.4-1+wheezy6) wheezy-security; urgency=high

  * Non-maintainer upload by the LTS Security Team.
  * Fix CVE-2017-14867: Git uses unsafe Perl scripts to support
    subcommands such as cvsserver, which allows attackers to execute
    arbitrary OS commands via shell metacharacters in a module name. The
    vulnerable code is reachable via git-shell even without CVS
    support. (Closes: #876854)

[dgit import package git 1:1.7.10.4-1+wheezy6]

8 years agoMerge git (1:1.7.10.4-1+wheezy5) import into refs/heads/workingbranch
Markus Koschany [Sun, 27 Aug 2017 13:51:22 +0000 (14:51 +0100)]
Merge git (1:1.7.10.4-1+wheezy5) import into refs/heads/workingbranch

8 years agogit (1:1.7.10.4-1+wheezy5) wheezy-security; urgency=high
Markus Koschany [Sun, 27 Aug 2017 13:51:22 +0000 (14:51 +0100)]
git (1:1.7.10.4-1+wheezy5) wheezy-security; urgency=high

  * Non-maintainer upload by the LTS team.
  *  Fix CVE-2017-1000117, arbitrary code execution issues via URLs:
      - reject ssh hostname that begins with a dash
      - factor out "looks like command line option" check
      - reject dashed arguments to $GIT_PROXY_COMMAND
      - ssh:// and local URLs: reject path to repositories that look like
        command line options

[dgit import package git 1:1.7.10.4-1+wheezy5]

8 years agoMerge git (1:1.7.10.4-1+wheezy4) import into refs/heads/workingbranch
Markus Koschany [Wed, 10 May 2017 16:40:45 +0000 (16:40 +0000)]
Merge git (1:1.7.10.4-1+wheezy4) import into refs/heads/workingbranch

8 years agogit (1:1.7.10.4-1+wheezy4) wheezy-security; urgency=high
Markus Koschany [Wed, 10 May 2017 16:40:45 +0000 (16:40 +0000)]
git (1:1.7.10.4-1+wheezy4) wheezy-security; urgency=high

  * Non-maintainer upload by the LTS team.
  * Fix CVE-2017-8386:
    Timo Schmid of ERNW GmbH discovered that the Git git-shell, a restricted
    login shell for Git-only SSH access, allows a user to run an interactive
    pager by causing it to spawn "git upload-pack --help".

[dgit import package git 1:1.7.10.4-1+wheezy4]

9 years agogit (1:1.7.10.4-1+wheezy3) wheezy-security; urgency=high
Salvatore Bonaccorso [Thu, 17 Mar 2016 20:48:34 +0000 (20:48 +0000)]
git (1:1.7.10.4-1+wheezy3) wheezy-security; urgency=high

  * Non-maintainer upload by the Security Team.
  * Fix remote code execution via buffer overflows (CVE-2016-2315,
    CVE-2016-2324) (Closes: #818318)

[dgit import package git 1:1.7.10.4-1+wheezy3]

13 years agoImport git_1.7.10.4.orig.tar.gz
Gerrit Pape [Fri, 8 Jun 2012 00:04:11 +0000 (01:04 +0100)]
Import git_1.7.10.4.orig.tar.gz

[dgit import orig git_1.7.10.4.orig.tar.gz]

13 years agoImport git_1.7.10.4.orig.tar.gz
Gerrit Pape [Fri, 8 Jun 2012 00:04:11 +0000 (00:04 +0000)]
Import git_1.7.10.4.orig.tar.gz

[dgit import orig git_1.7.10.4.orig.tar.gz]