提交 0114f713 编写于 作者: J Junio C Hamano

Git 2.13.7

Signed-off-by: NJunio C Hamano <gitster@pobox.com>
上级 8528c31d
Git v2.13.7 Release Notes
=========================
Fixes since v2.13.6
-------------------
* Submodule "names" come from the untrusted .gitmodules file, but we
blindly append them to $GIT_DIR/modules to create our on-disk repo
paths. This means you can do bad things by putting "../" into the
name. We now enforce some rules for submodule names which will cause
Git to ignore these malicious names (CVE-2018-11235).
Credit for finding this vulnerability and the proof of concept from
which the test script was adapted goes to Etienne Stalmans.
* It was possible to trick the code that sanity-checks paths on NTFS
into reading random piece of memory (CVE-2018-11233).
Credit for fixing for these bugs goes to Jeff King, Johannes
Schindelin and others.
#!/bin/sh
GVF=GIT-VERSION-FILE
DEF_VER=v2.13.6
DEF_VER=v2.13.7
LF='
'
......
Documentation/RelNotes/2.13.6.txt
\ No newline at end of file
Documentation/RelNotes/2.13.7.txt
\ No newline at end of file
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册