[Discuss] Git Vulnerability

Alan W. Irwin irwin at beluga.phys.uvic.ca
Fri Dec 19 13:06:48 PST 2014


On 2014-12-19 07:13-0800 Adam Parkin wrote:

> Doesn't affect most Linux users (though they're still encouraged to upgrade
> as well), but if you're using Git on a case-insensitive filesystem there's
> been a fairly nasty vulnerability discovered:
>
> http://article.gmane.org/gmane.linux.kernel/1853266
> https://github.com/blog/1938-git-client-vulnerability-announced
> http://git-blame.blogspot.com.es/2014/12/git-1856-195-205-214-and-221-and.html

Thanks for bringing this to the attention of the list.  For this to
actually turn into an exploit the attacker needs write access to the
git repository which is generally difficult to achieve. So it sounds
like a "due diligence" git client security update is needed (as
opposed to an emergency security update) for the only platforms
affected (Mac OS X and Windows).

I am glad to see the free software mentality is still alive and well;
in the first URL above the git developers gave a big thanks to the
mercurial (!) developers for drawing this issue to their attention.
And kudos to the git developers for paying attention to the mercurial
developers. I just don't think you would see such cooperation and
trust between proprietary software projects.

Alan
__________________________
Alan W. Irwin

Astronomical research affiliation with Department of Physics and Astronomy,
University of Victoria (astrowww.phys.uvic.ca).

Programming affiliations with the FreeEOS equation-of-state
implementation for stellar interiors (freeeos.sf.net); the Time
Ephemerides project (timeephem.sf.net); PLplot scientific plotting
software package (plplot.sf.net); the libLASi project
(unifont.org/lasi); the Loads of Linux Links project (loll.sf.net);
and the Linux Brochure Project (lbproject.sf.net).
__________________________

Linux-powered Science
__________________________


More information about the Discuss mailing list