3 ms·
Note: if you're using Ubuntu, there is a semi-official PPA that has a non-vulnerable version (2.7.3): https://launchpad.net/~git-core/+archive/ubuntu/ppa https:
by krallin 11y ago
Note: if you're using Ubuntu, there is a semi-official PPA that has a non-vulnerable version (2.7.3): https://launchpad.net/~git-core/+archive/ubuntu/ppa https://launchpad.net/~git-core/+archive/ubuntu/ppa
- wyldfire 11y agoBut a fix should come via the normal update channel soon? I'm on wily, should I expect to add this PPA or risk vulnerability?
- voltagex_ 11y agoUbuntu should announce the fix at https://www.ubuntu.com/usn/ https://www.ubuntu.com/usn/ but I can't load the page right now. (removed DSA link as per advice below)
- 0x0 11y agoThat Debian advisory is a different, older vulnerability. Looks like they know about it but haven't released anything yet: https://security-tracker.debian.org/tracker/source-package/git https://security-tracker.debian.org/tracker/source-package/g...
- voltagex_ 11y agoOops, thanks.
- reedloden 11y agohttps://bugs.launchpad.net/ubuntu/+source/git/+bug/1557787 https://bugs.launchpad.net/ubuntu/+source/git/+bug/1557787 is the tracking bug for this issue. Seems like it's fixed on xenial but not yet in older releases.
- krallin 11y agoUnfortunately it looks like the distros have not been particularly diligent about releasing a fix via the security channel (according to the article), so this PPA is a workaround