Skip to content

Commit d0832b2

Browse files
committed
Git 2.14.5
Signed-off-by: Junio C Hamano <[email protected]>
1 parent 273c614 commit d0832b2

File tree

3 files changed

+18
-2
lines changed

3 files changed

+18
-2
lines changed

Documentation/RelNotes/2.14.5.txt

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
Git v2.14.5 Release Notes
2+
=========================
3+
4+
This release is to address the recently reported CVE-2018-17456.
5+
6+
Fixes since v2.14.4
7+
-------------------
8+
9+
* Submodules' "URL"s come from the untrusted .gitmodules file, but
10+
we blindly gave it to "git clone" to clone submodules when "git
11+
clone --recurse-submodules" was used to clone a project that has
12+
such a submodule. The code has been hardened to reject such
13+
malformed URLs (e.g. one that begins with a dash).
14+
15+
Credit for finding and fixing this vulnerability goes to joernchen
16+
and Jeff King, respectively.

GIT-VERSION-GEN

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
#!/bin/sh
22

33
GVF=GIT-VERSION-FILE
4-
DEF_VER=v2.14.4
4+
DEF_VER=v2.14.5
55

66
LF='
77
'

RelNotes

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
Documentation/RelNotes/2.14.4.txt
1+
Documentation/RelNotes/2.14.5.txt

0 commit comments

Comments
 (0)