]> git.ipfire.org Git - thirdparty/git.git/commitdiff
Git 2.17.6 v2.17.6
authorJohannes Schindelin <johannes.schindelin@gmx.de>
Fri, 29 Jan 2021 18:13:11 +0000 (19:13 +0100)
committerJohannes Schindelin <johannes.schindelin@gmx.de>
Fri, 12 Feb 2021 14:47:02 +0000 (15:47 +0100)
Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>
Documentation/RelNotes/2.17.6.txt [new file with mode: 0644]
GIT-VERSION-GEN
RelNotes

diff --git a/Documentation/RelNotes/2.17.6.txt b/Documentation/RelNotes/2.17.6.txt
new file mode 100644 (file)
index 0000000..2f181e8
--- /dev/null
@@ -0,0 +1,16 @@
+Git v2.17.6 Release Notes
+=========================
+
+This release addresses the security issues CVE-2021-21300.
+
+Fixes since v2.17.5
+-------------------
+
+ * CVE-2021-21300:
+   On case-insensitive file systems with support for symbolic links,
+   if Git is configured globally to apply delay-capable clean/smudge
+   filters (such as Git LFS), Git could be fooled into running
+   remote code during a clone.
+
+Credit for finding and fixing this vulnerability goes to Matheus
+Tavares, helped by Johannes Schindelin.
index 85d9db5600072dc356e60e4ba2cea046e06cfd74..46755850692d9ab13c7e57fdb6bd4e8b11d5934e 100755 (executable)
@@ -1,7 +1,7 @@
 #!/bin/sh
 
 GVF=GIT-VERSION-FILE
-DEF_VER=v2.17.5
+DEF_VER=v2.17.6
 
 LF='
 '
index 07012e884f30dc6c8b76c3cf3d7d832b895879e1..04bc17f6c5eb9e4cf267e696ffea9cd646b2d48b 120000 (symlink)
--- a/RelNotes
+++ b/RelNotes
@@ -1 +1 @@
-Documentation/RelNotes/2.17.5.txt
\ No newline at end of file
+Documentation/RelNotes/2.17.6.txt
\ No newline at end of file