]> git.ipfire.org Git - thirdparty/git.git/commit
Merge branch 'ah/fix-open-with-stdin'
authorJohannes Sixt <j6t@kdbg.org>
Wed, 14 May 2025 16:27:05 +0000 (18:27 +0200)
committerTaylor Blau <me@ttaylorr.com>
Fri, 23 May 2025 21:04:30 +0000 (17:04 -0400)
commit4e7e3b792e6973e09de6ddc191b86bbc245c53dd
treeb2ba96a1873441245fda2cc9df47af7aef9f24b7
parent664d4fa692cb8637a7c9297c94abf0de8593e585
parent8e3070aa5e331be45d4d03e3be41f84494fce129
Merge branch 'ah/fix-open-with-stdin'

This addresses CVE-2025-27614, Arbitrary command execution with Gitk:

A Git repository can be crafted in such a way that with some social
engineering a user who has cloned the repository can be tricked into
running any script (e.g., Bourne shell, Perl, Python, ...) supplied by
the attacker by invoking `gitk filename`, where `filename` has a
particular structure. The script is run with the privileges of the user.

Signed-off-by: Johannes Sixt <j6t@kdbg.org>
gitk-git/gitk