File tree Expand file tree Collapse file tree 3 files changed +18
-2
lines changed
Expand file tree Collapse file tree 3 files changed +18
-2
lines changed Original file line number Diff line number Diff line change 1+ Git v2.17.4 Release Notes
2+ =========================
3+
4+ This release is to address the security issue: CVE-2020-5260
5+
6+ Fixes since v2.17.3
7+ -------------------
8+
9+ * With a crafted URL that contains a newline in it, the credential
10+ helper machinery can be fooled to give credential information for
11+ a wrong host. The attack has been made impossible by forbidding
12+ a newline character in any value passed via the credential
13+ protocol.
14+
15+ Credit for finding the vulnerability goes to Felix Wilhelm of Google
16+ Project Zero.
Original file line number Diff line number Diff line change 11#! /bin/sh
22
33GVF=GIT-VERSION-FILE
4- DEF_VER=v2.17.3
4+ DEF_VER=v2.17.4
55
66LF='
77'
Original file line number Diff line number Diff line change 1- Documentation/RelNotes/2.17.3 .txt
1+ Documentation/RelNotes/2.17.4 .txt
You can’t perform that action at this time.
0 commit comments