summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Raspbian forward pporter [Tue, 3 Oct 2017 01:50:14 +0000 (02:50 +0100)]
Merge version 1:1.7.10.4-1+wheezy5+rpi1 and 1:1.7.10.4-1+wheezy6 to produce 1:1.7.10.4-1+wheezy6+rpi1
Antoine Beaupré [Mon, 2 Oct 2017 19:47:26 +0000 (20:47 +0100)]
Merge git (1:1.7.10.4-1+wheezy6) import into refs/heads/workingbranch
Antoine Beaupré [Mon, 2 Oct 2017 19:47:26 +0000 (20:47 +0100)]
git (1:1.7.10.4-1+wheezy6) wheezy-security; urgency=high
* Non-maintainer upload by the LTS Security Team.
* Fix CVE-2017-14867: Git uses unsafe Perl scripts to support
subcommands such as cvsserver, which allows attackers to execute
arbitrary OS commands via shell metacharacters in a module name. The
vulnerable code is reachable via git-shell even without CVS
support. (Closes: #876854)
[dgit import package git 1:1.7.10.4-1+wheezy6]
Raspbian forward porter [Fri, 1 Sep 2017 04:07:56 +0000 (05:07 +0100)]
Merge git (1:1.7.10.4-1+wheezy5+rpi1) import into refs/heads/workingbranch
Raspbian forward porter [Fri, 1 Sep 2017 04:07:56 +0000 (05:07 +0100)]
git (1:1.7.10.4-1+wheezy5+rpi1) wheezy-staging; urgency=medium
[changes brought forward from 1:1.7.10.4-1+wheezy1+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Sun, 25 Nov 2012 13:13:58 +0000]
* Disable testsuite
[changes brought forward from 1:1.7.10.4-1+wheezy1+rpi2 by Peter Michael Green <plugwash@raspbian.org> at Sun, 14 Apr 2013 13:54:01 +0000]
* Adopt patches from sid version 1:1.7.10.4-2 for new subversion, renumber
them to high numbers so they stay at the end of the list in the face of
future wheezy changes.
* 0113...0130: new from the upstream 'master' branch: git svn:
adapt to svn 1.7 changes:
* normalize paths and URLs passed to Subversion (thx Michael G.
Schwern; closes: #678137)
* use correct "svn cp" syntax when checking git svn's mangling
of @-signs in branch names (svn became stricter).
* commit filetype changes between a regular file and symlink as
replacement (deletion followed by addition) instead of
modification of files. Otherwise, clients pulling the change
with "svn update" hit an assertion failure (svn issue 4091).
* Renable testsuite
[dgit import package git 1:1.7.10.4-1+wheezy5+rpi1]
Markus Koschany [Sun, 27 Aug 2017 13:51:22 +0000 (14:51 +0100)]
Merge git (1:1.7.10.4-1+wheezy5) import into refs/heads/workingbranch
Markus Koschany [Sun, 27 Aug 2017 13:51:22 +0000 (14:51 +0100)]
git (1:1.7.10.4-1+wheezy5) wheezy-security; urgency=high
* Non-maintainer upload by the LTS team.
* Fix CVE-2017-
1000117, arbitrary code execution issues via URLs:
- reject ssh hostname that begins with a dash
- factor out "looks like command line option" check
- reject dashed arguments to $GIT_PROXY_COMMAND
- ssh:// and local URLs: reject path to repositories that look like
command line options
[dgit import package git 1:1.7.10.4-1+wheezy5]
Markus Koschany [Wed, 10 May 2017 16:40:45 +0000 (16:40 +0000)]
Merge git (1:1.7.10.4-1+wheezy4) import into refs/heads/workingbranch
Markus Koschany [Wed, 10 May 2017 16:40:45 +0000 (16:40 +0000)]
git (1:1.7.10.4-1+wheezy4) wheezy-security; urgency=high
* Non-maintainer upload by the LTS team.
* Fix CVE-2017-8386:
Timo Schmid of ERNW GmbH discovered that the Git git-shell, a restricted
login shell for Git-only SSH access, allows a user to run an interactive
pager by causing it to spawn "git upload-pack --help".
[dgit import package git 1:1.7.10.4-1+wheezy4]
Salvatore Bonaccorso [Thu, 17 Mar 2016 20:48:34 +0000 (20:48 +0000)]
git (1:1.7.10.4-1+wheezy3) wheezy-security; urgency=high
* Non-maintainer upload by the Security Team.
* Fix remote code execution via buffer overflows (CVE-2016-2315,
CVE-2016-2324) (Closes: #818318)
[dgit import package git 1:1.7.10.4-1+wheezy3]
Gerrit Pape [Fri, 8 Jun 2012 00:04:11 +0000 (01:04 +0100)]
Import git_1.7.10.4.orig.tar.gz
[dgit import orig git_1.7.10.4.orig.tar.gz]
Gerrit Pape [Fri, 8 Jun 2012 00:04:11 +0000 (00:04 +0000)]
Import git_1.7.10.4.orig.tar.gz
[dgit import orig git_1.7.10.4.orig.tar.gz]