4 ms·
> A few months ago, I submitted an issue in the Gitg issue tracker. The maintainer replied to me: “Reviewing ssh feature, it is not even touched on gitg or libg
by Denvercoder9 6y ago
> A few months ago, I submitted an issue in the Gitg issue tracker. The maintainer replied to me: “Reviewing ssh feature, it is not even touched on gitg or libgit2-glib, just a dependency on libgit2, […]“.(Source)
> Although it comes with an unpatched libssh2, Gitg does not use the part that contains the vulnerability.
This conclusion is plain false. The maintainer comment he quotes only says that gitg doesn't directly use libssh2 (so they can't enforce a version constraint on it), not that it doesn't use it all. It's very likely that gitg does actually use the vulnerable libssh2 if you use it to clone a repository over SSH (which it can do).