git 1:2.27.0~rc0-1ubuntu1 source package in Ubuntu
Changelog
git (1:2.27.0~rc0-1ubuntu1) groovy; urgency=low * Merge from Debian unstable. Remaining changes: - Build diff-highlight in the contrib dir (closes: #868871, LP: #1713690) - Don't build-depend on subversion on i386, it is not reasonable to support on the partial arch. * Drop security update patches, included upstream. git (1:2.27.0~rc0-1) unstable; urgency=low * new upstream release candidate (see RelNotes/2.27.0.txt). git (1:2.26.2-1) unstable; urgency=high * new upstream point release (see RelNotes/2.26.2.txt). * Addresses the security issue CVE-2020-11008. With a crafted URL that contains a newline or empty host, or lacks a scheme, the credential helper machinery can be fooled into providing credential information that is not appropriate for the protocol in use and host being contacted. Unlike the vulnerability fixed in 2.26.1, the credentials are not for a host of the attacker's choosing. Instead, they are for an unspecified host, based on how the configured credential helper handles an absent "host" parameter. The attack has been made impossible by refusing to work with underspecified credential patterns. Thanks to Carlo Arenas for reporting that Git was still vulnerable, Felix Wilhelm for providing the proof of concept demonstrating this issue, and Jeff King for promptly providing a corrected fix. Tested using the proof of concept at https://crbug.com/project-zero/2021. git (1:2.26.1-1) unstable; urgency=high * new upstream point release (see RelNotes/2.26.1.txt). * Addresses the security issue CVE-2020-5260. With a crafted URL that contains a newline, the credential helper machinery can be fooled to supply credential information for the wrong host. The attack has been made impossible by forbidding a newline character in any value passed via the credential protocol. Thanks to Felix Wilhelm of Google Project Zero for finding this vulnerability and Jeff King for fixing it. git (1:2.26.0-2) unstable; urgency=low * fixes to the (newly default) rebase --merge backend: * honor GIT_REFLOG_ACTION (thx Ian Jackson and Elijah Newren; closes: #955152). * avoid "nothing to do" error when fast-forwarding a branch with rebase.abbreviateCommands=true (thx Jan Alexander Steffens and Alban Gruin). * debian/control: downgrade Recommends by git-all on git-daemon-run to Suggests. The git-all package is a "batteries included" full installation of Git. Automatically running a daemon is not useful to most of its users. git (1:2.26.0-1) unstable; urgency=low * new upstream release (see RelNotes/2.26.0.txt). git (1:2.26.0~rc2-1) unstable; urgency=low * new upstream release candidate (see RelNotes/2.26.0.txt). -- Steve Langasek <email address hidden> Wed, 20 May 2020 16:48:49 -0700
Upload details
- Uploaded by:
- Steve Langasek
- Uploaded to:
- Groovy
- Original maintainer:
- Ubuntu Developers
- Architectures:
- any all
- Section:
- vcs
- Urgency:
- Very Urgent
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
git_2.27.0~rc0.orig.tar.xz | 5.8 MiB | b5680b932d884bf07e00ac813bcf95c2577405024bc540b272ff27183c9a950e |
git_2.27.0~rc0-1ubuntu1.debian.tar.xz | 636.7 KiB | ddbbf243f0340d67084f2b257bc016a934c666ade0e41243ade6028b2c4954a6 |
git_2.27.0~rc0-1ubuntu1.dsc | 2.9 KiB | 0f18f57ddced1b3949656af72dd86729195c93634f1b4b9cbf9f20f9e7c77400 |
Available diffs
Binary packages built by this source
- git: No summary available for git in ubuntu groovy.
No description available for git in ubuntu groovy.
- git-all: No summary available for git-all in ubuntu groovy.
No description available for git-all in ubuntu groovy.
- git-cvs: No summary available for git-cvs in ubuntu groovy.
No description available for git-cvs in ubuntu groovy.
- git-daemon-run: No summary available for git-daemon-run in ubuntu groovy.
No description available for git-daemon-run in ubuntu groovy.
- git-daemon-sysvinit: No summary available for git-daemon-sysvinit in ubuntu groovy.
No description available for git-daemon-sysvinit in ubuntu groovy.
- git-dbgsym: No summary available for git-dbgsym in ubuntu groovy.
No description available for git-dbgsym in ubuntu groovy.
- git-doc: No summary available for git-doc in ubuntu groovy.
No description available for git-doc in ubuntu groovy.
- git-el: No summary available for git-el in ubuntu groovy.
No description available for git-el in ubuntu groovy.
- git-email: No summary available for git-email in ubuntu groovy.
No description available for git-email in ubuntu groovy.
- git-gui: No summary available for git-gui in ubuntu groovy.
No description available for git-gui in ubuntu groovy.
- git-man: No summary available for git-man in ubuntu groovy.
No description available for git-man in ubuntu groovy.
- git-mediawiki: No summary available for git-mediawiki in ubuntu groovy.
No description available for git-mediawiki in ubuntu groovy.
- git-svn: No summary available for git-svn in ubuntu groovy.
No description available for git-svn in ubuntu groovy.
- gitk: No summary available for gitk in ubuntu groovy.
No description available for gitk in ubuntu groovy.
- gitweb: No summary available for gitweb in ubuntu groovy.
No description available for gitweb in ubuntu groovy.