Format: 1.8 Date: Fri, 05 Oct 2018 16:59:03 -0700 Source: git Binary: git git-man git-core git-doc git-arch git-cvs git-svn git-mediawiki git-email git-daemon-run git-daemon-sysvinit git-gui gitk git-el gitweb git-all Architecture: all amd64 amd64_translations Version: 1:2.7.4-0ubuntu1.5 Distribution: xenial Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Steve Beattie Description: git - fast, scalable, distributed revision control system git-all - fast, scalable, distributed revision control system (all subpacka git-arch - fast, scalable, distributed revision control system (arch interop git-core - fast, scalable, distributed revision control system (obsolete) git-cvs - fast, scalable, distributed revision control system (cvs interope git-daemon-run - fast, scalable, distributed revision control system (git-daemon s git-daemon-sysvinit - fast, scalable, distributed revision control system (git-daemon s git-doc - fast, scalable, distributed revision control system (documentatio git-el - fast, scalable, distributed revision control system (emacs suppor git-email - fast, scalable, distributed revision control system (email add-on git-gui - fast, scalable, distributed revision control system (GUI) git-man - fast, scalable, distributed revision control system (manual pages git-mediawiki - fast, scalable, distributed revision control system (MediaWiki in git-svn - fast, scalable, distributed revision control system (svn interope gitk - fast, scalable, distributed revision control system (revision tre gitweb - fast, scalable, distributed revision control system (web interfac Changes: git (1:2.7.4-0ubuntu1.5) xenial-security; urgency=medium . * SECURITY UPDATE: arbitrary code execution via submodule URLs and paths in .gitsubmodules. - 0001-submodule-helper-use-to-signal-end-of-clone-options.patch, 0002-submodule-config-ban-submodule-urls-that-start-with-.patch, 0003-submodule-config-ban-submodule-paths-that-start-with.patch: disallow urls and files that begin with '--'. - 0004-fsck-detect-submodule-urls-starting-with-dash.patch, 0005-fsck-detect-submodule-paths-starting-with-dash.patch: reject gitmodules that contain submdule urls and files that begin with '--'. - CVE-2018-17456 * SECURITY UPDATE: incomplete fix for CVE-2017-14867 - 0006-cvsimport-apply-shell-quoting-regex-globally.patch: escape all instances of backticks Checksums-Sha1: dfaeac782245fed440bf6ba0a419218e4d4f8446 6402 git-all_2.7.4-0ubuntu1.5_all.deb 1f72aa9b9228ac3a5afb3bc52feb18021c9dadbe 19656 git-arch_2.7.4-0ubuntu1.5_all.deb 553ea6b95a491d49ad2357e3b1471d7a5d48253f 1472 git-core_2.7.4-0ubuntu1.5_all.deb 26c4aa610f2c7955dab0cc86128d622936e47e47 69322 git-cvs_2.7.4-0ubuntu1.5_all.deb 4e959645091f0a744749a84dbcb2fb9e12b34fff 7906 git-daemon-run_2.7.4-0ubuntu1.5_all.deb 6379e79aea04ea6e8c503c00ba5b9b52fe199767 8896 git-daemon-sysvinit_2.7.4-0ubuntu1.5_all.deb d140d8fe0409482006aea709dff0a3686f914ebb 877820 git-doc_2.7.4-0ubuntu1.5_all.deb 5799b4b973aef74772061c931127a14fdf7d039e 25778 git-el_2.7.4-0ubuntu1.5_all.deb bb44df159f7bfe5b67f07eb651fd2a1ce5cba349 28284 git-email_2.7.4-0ubuntu1.5_all.deb 11e963b0e9f1fe6a39a7f5b3c442b11e9d5aa860 207510 git-gui_2.7.4-0ubuntu1.5_all.deb 93e5608afe39df7c7baa18305875695b377e2df2 735926 git-man_2.7.4-0ubuntu1.5_all.deb 13ab205188e4eb1aeb23f6f1be0680d1cb7f0a4e 21814 git-mediawiki_2.7.4-0ubuntu1.5_all.deb 8d257304fe6bf25ff5a30c07e0512ace588af282 90930 git-svn_2.7.4-0ubuntu1.5_all.deb 29613092985f04f948591652ae26a4a718eff19a 2714026 git_2.7.4-0ubuntu1.5_amd64.deb 19847afae954c9304002485143f1d19a995331f6 2175630 git_2.7.4-0ubuntu1.5_amd64_translations.tar.gz c4771d9278f892d80296f46a6178753267eaf20f 131916 gitk_2.7.4-0ubuntu1.5_all.deb 3892e06066fb45a86d56075152ed83262697750d 10656 gitweb_2.7.4-0ubuntu1.5_all.deb Checksums-Sha256: 830848acdd7b518e55e956d9b6da110966c3eee6c7a123ce180df882cbbf3740 6402 git-all_2.7.4-0ubuntu1.5_all.deb 073353466e714893dd72fbd70b67a2cd169f2305f65d9f8a0aa4cc2753a4bb1d 19656 git-arch_2.7.4-0ubuntu1.5_all.deb d07a8ea6d83be600a5b92eb1817027dbc806806cb688e08e05fac020e73c8f3a 1472 git-core_2.7.4-0ubuntu1.5_all.deb 52104006d2b7c0912236c65fc4ccc7fef89b1472ad794263b0996284b00c04b6 69322 git-cvs_2.7.4-0ubuntu1.5_all.deb f9e1f954cf889c0fc815d312af590238aec562192fb840dc92210a3bdc6b1d7b 7906 git-daemon-run_2.7.4-0ubuntu1.5_all.deb c07450bbf2fd07c42ac927714a6aeb3d92fd5bf60ba2b51eb8c61b62f87bbe90 8896 git-daemon-sysvinit_2.7.4-0ubuntu1.5_all.deb 72ca4c3a8d752142dcc624ff1267976a09fd46c5d9ca3b54db61164eb0840cf1 877820 git-doc_2.7.4-0ubuntu1.5_all.deb 090fbc064dc55949e539ca202d8e8cee9d7d99b3a32759303c4bedb109605720 25778 git-el_2.7.4-0ubuntu1.5_all.deb 4baa996958753b232645c3d01f1974dc86f999250d04f84bccb3e4b5bded499a 28284 git-email_2.7.4-0ubuntu1.5_all.deb 4410cd9457798bf848b9cb2f0ca339f12ff9c304eef8c2beb9eae2d36675dd02 207510 git-gui_2.7.4-0ubuntu1.5_all.deb fe33869c7a1924979a0cd183580348fe440ed75cc4a5e01307254d25c74e9d49 735926 git-man_2.7.4-0ubuntu1.5_all.deb e93d6cb781a02895863986f34356d1182e0e868e30a0ecd4df27825137b89387 21814 git-mediawiki_2.7.4-0ubuntu1.5_all.deb e67c8873dc1a35939c7261c3b9a762daf8754675ffebd52ff908e79863442cec 90930 git-svn_2.7.4-0ubuntu1.5_all.deb 53a5b2727564af1ab57bc250d64ba141993ca6fbb91895a229f8095005ac5b6d 2714026 git_2.7.4-0ubuntu1.5_amd64.deb 9d5036f9a16f633cf6d3416ff952203c52ae66be3e5268c365f5b2a9695086fc 2175630 git_2.7.4-0ubuntu1.5_amd64_translations.tar.gz b4255f59872ece9d244ad29956022634649acb6939fd629c9f857737b650d582 131916 gitk_2.7.4-0ubuntu1.5_all.deb 5836fe0e1362f2ae03f437da95536e384c6d239b9f27d300a5809fb46ba6c49d 10656 gitweb_2.7.4-0ubuntu1.5_all.deb Files: 3baf66a6a3940eba15efb38a16ccb87f 6402 vcs optional git-all_2.7.4-0ubuntu1.5_all.deb 829477eff81535190e93f394119ab4bf 19656 vcs optional git-arch_2.7.4-0ubuntu1.5_all.deb 68a3e4410ee673cf12e351db28038338 1472 vcs optional git-core_2.7.4-0ubuntu1.5_all.deb 3f0f249dca71a2eb9f5a979ae52d0aca 69322 vcs optional git-cvs_2.7.4-0ubuntu1.5_all.deb 439106c21cb4806390bece4988951d1b 7906 vcs optional git-daemon-run_2.7.4-0ubuntu1.5_all.deb ffc3519221f67993e65d34edb3b3a50c 8896 vcs extra git-daemon-sysvinit_2.7.4-0ubuntu1.5_all.deb 3e5dc52bc858a6b6ef691f490fce47d8 877820 doc optional git-doc_2.7.4-0ubuntu1.5_all.deb 372d83cd8ed7a2b39d120aa5a32376c6 25778 vcs optional git-el_2.7.4-0ubuntu1.5_all.deb 3bdfb3681051532ee06b30e14653f907 28284 vcs optional git-email_2.7.4-0ubuntu1.5_all.deb 365fa62613508ba634e3dc9bde841544 207510 vcs optional git-gui_2.7.4-0ubuntu1.5_all.deb 1cd68dcd2c1fa82161aa1faf766acd14 735926 doc optional git-man_2.7.4-0ubuntu1.5_all.deb 9df871e38b73d621c273281633c6c766 21814 vcs optional git-mediawiki_2.7.4-0ubuntu1.5_all.deb 06970047b12b3f5854655c52f34376a3 90930 vcs optional git-svn_2.7.4-0ubuntu1.5_all.deb 4e62ca17c6e994140b85020ae525ac47 2714026 vcs optional git_2.7.4-0ubuntu1.5_amd64.deb 8481694eebf395b37edf75a023d75dff 2175630 raw-translations - git_2.7.4-0ubuntu1.5_amd64_translations.tar.gz 2d6141df3bf32837185411e1ee0ff9d3 131916 vcs optional gitk_2.7.4-0ubuntu1.5_all.deb ed851467b72adbdefd7b10d29a0f1a7d 10656 vcs optional gitweb_2.7.4-0ubuntu1.5_all.deb Original-Maintainer: Gerrit Pape