Upgrade Git for CVE-2018-17456 |
||||||
Issue descriptionPlease upgrade Git to one of the versions mentioned at https://public-inbox.org/git/xmqqy3bcuy3l.fsf@gitster-ct.c.googlers.com/
,
Oct 5
,
Oct 5
I think the most important is to release 2.18.1 to devs on Win, Pri0.5-like important. Updating bots can be handled with Pri-1.
,
Oct 5
Regarding Windows, keep in mind P.S. Folks at Microsoft tried to follow the known exploit recipe on Git for Windows (but not Cygwin or other Git implementations on Windows) and found that the recipe (or its variants they can think of) would not make their system vulnerable.
,
Oct 5
,
Oct 5
atm, there is no git 2.18.1 for win released yet https://github.com/git-for-windows/git/releases , only 2.19.1 Given the P.S. I've missed (thanks, jrn@) in #c4, i think we can wait a bit for iannucci@ to finish his work on new pipeline of third_package releases and then take on this bug.
,
Oct 18
,
Oct 18
|
||||||
►
Sign in to add a comment |
||||||
Comment 1 by tandrii@chromium.org
, Oct 5