Path to this page:
Subject: CVS commit: pkgsrc/devel
From: Leonardo Taccari
Date: 2021-03-09 22:15:20
Message id: 20210309211520.3FAADFA95@cvs.NetBSD.org
Log Message:
git: Update to 2.30.2
Changes:
2.30.2
======
This release addresses the security issues CVE-2021-21300.
* CVE-2021-21300:
On case-insensitive file systems with support for symbolic links,
if Git is configured globally to apply delay-capable clean/smudge
filters (such as Git LFS), Git could be fooled into running
remote code during a clone.
Credit for finding and fixing this vulnerability goes to Matheus
Tavares, helped by Johannes Schindelin.
Files: