summaryrefslogtreecommitdiff
path: root/Documentation/RelNotes/2.20.2.txt
diff options
context:
space:
mode:
authorJunio C Hamano <gitster@pobox.com>2019-12-10 06:17:55 (GMT)
committerJunio C Hamano <gitster@pobox.com>2019-12-10 06:17:55 (GMT)
commit7034cd094bda4edbcdff7fad1a28fcaaf9b9a040 (patch)
treee0b837c5e5a2ea2fce3255ef59fd981e2bd30374 /Documentation/RelNotes/2.20.2.txt
parent559c6fc317f92a0a3994f816d3513cd322745852 (diff)
parent53a06cf39b756eddfe4a2a34da93e3d04eb7b728 (diff)
downloadgit-7034cd094bda4edbcdff7fad1a28fcaaf9b9a040.zip
git-7034cd094bda4edbcdff7fad1a28fcaaf9b9a040.tar.gz
git-7034cd094bda4edbcdff7fad1a28fcaaf9b9a040.tar.bz2
Sync with Git 2.24.1
Diffstat (limited to 'Documentation/RelNotes/2.20.2.txt')
-rw-r--r--Documentation/RelNotes/2.20.2.txt18
1 files changed, 18 insertions, 0 deletions
diff --git a/Documentation/RelNotes/2.20.2.txt b/Documentation/RelNotes/2.20.2.txt
new file mode 100644
index 0000000..8e680cb
--- /dev/null
+++ b/Documentation/RelNotes/2.20.2.txt
@@ -0,0 +1,18 @@
+Git v2.20.2 Release Notes
+=========================
+
+This release merges up the fixes that appear in v2.14.6, v2.15.4
+and in v2.17.3, addressing the security issues CVE-2019-1348,
+CVE-2019-1349, CVE-2019-1350, CVE-2019-1351, CVE-2019-1352,
+CVE-2019-1353, CVE-2019-1354, and CVE-2019-1387; see the release notes
+for those versions for details.
+
+The change to disallow `submodule.<name>.update=!command` entries in
+`.gitmodules` which was introduced v2.15.4 (and for which v2.17.3
+added explicit fsck checks) fixes the vulnerability in v2.20.x where a
+recursive clone followed by a submodule update could execute code
+contained within the repository without the user explicitly having
+asked for that (CVE-2019-19604).
+
+Credit for finding this vulnerability goes to Joern Schneeweisz,
+credit for the fixes goes to Jonathan Nieder.