[ANNOUNCE] GIT 1.1.5



The latest maintenance release GIT 1.1.5 is available at the
usual places:

http://www.kernel.org/pub/software/scm/git/

git-1.1.5.tar.{gz,bz2} (tarball)
RPMS/$arch/git-*-1.1.5-1.$arch.rpm (RPM)

Mark Wooding noticed that there is a bug in git-checkout-index
to overflow its internal buffer, if you construct a blob that
records an insanely long symbolic link in your index file and
try to check it out. This makes it dump core or worse.

The fix for this problem is the only change from v1.1.4. The
master branch has been updated with the same fix (so has "pu").


---

By the way, "dump core or worse" is a subtle way to say that
this is a security fix. To be victimized, you have to somehow
first get such a bogus symbolic link in your index. Merging
with somebody of dubious trustworthiness is a way to do so;
please practice safe merge ;-).

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/



Relevant Pages

  • Re: no responding, when i use rlock function
    ... When i using 2 computer the run this application, one computer can append ... Did you delete the index file when you tried it? ... but if i remove and create the index again, the it still no responding? ... how can i fix the problem? ...
    (microsoft.public.fox.helpwanted)
  • Re: no responding, when i use rlock function
    ... Did you delete the index file when you tried it? ... how can i fix the problem? ... but another computer have no responding, this 2 computer also using winXP ... only one table use APPEND BLANK will no responding ...
    (microsoft.public.fox.helpwanted)
  • The update cannot be started because the content sources cannot be accessed.
    ... Fix the errors and try the update again. ... Context: Application 'Search', Catalog 'index file on the search ...
    (microsoft.public.sharepoint.portalserver)
  • Symbolic link not allowed:
    ... I have the "Symbolic link not allowed:" error that I don't know how ... it to fix it. ... You don't have permission to access /faculty/quoc on this server. ... a 403 Forbidden error was encountered while trying to ...
    (comp.infosystems.www.servers.unix)
  • Re: RH8 Cant Get Mozilla 1.5 to Load Java
    ... > site with Mozilla 1.5 that needs Java, it doesn't load. ... How can fix this? ... You need to make a symbolic link from your ...
    (linux.redhat)