New issue
Advanced search Search tips

Issue 892681 link

Starred by 1 user

Issue metadata

Status: Available
Owner: ----
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 1
Type: Bug

Blocked on:
issue 877775



Sign in to add a comment

Upgrade Git for CVE-2018-17456

Project Member Reported by jrn@google.com, Oct 5

Issue description

Please upgrade Git to one of the versions mentioned at
https://public-inbox.org/git/xmqqy3bcuy3l.fsf@gitster-ct.c.googlers.com/

 
Given that we can't release 2.18 on bots,
this means upgrading to 2.17.2 on bots.

Additionally, 2.18 has been released to Win devs already. So, devs should get 2.18.1.
Cc: iannucci@chromium.org
I think the most important is to release 2.18.1 to devs on Win, Pri0.5-like important.

Updating bots can be handled with Pri-1.
Regarding Windows, keep in mind

P.S. Folks at Microsoft tried to follow the known exploit recipe on
Git for Windows (but not Cygwin or other Git implementations on
Windows) and found that the recipe (or its variants they can think
of) would not make their system vulnerable.

Components: -Infra>Git>Admin Infra>SDK
Blockedon: 877775
Status: Available (was: Untriaged)
atm, there is no git 2.18.1 for win released yet https://github.com/git-for-windows/git/releases  , only 2.19.1

Given the P.S. I've missed (thanks, jrn@) in #c4, i think we can wait a bit for iannucci@ to finish his work on new pipeline of third_package releases and then take on this bug.
Cc: iannu...@google.com
Cc: -iannucci@chromium.org

Sign in to add a comment