From mboxrd@z Thu Jan 1 00:00:00 1970 From: Tobias Geerinckx-Rice Subject: Re: Git 2.17.1 security update CVE-2018-{11234,11235} Date: Tue, 29 May 2018 22:14:59 +0200 Message-ID: <871sdumd6k.fsf@lapdog.tobias.gr> References: <20180529200748.GA23835@jasmine.lan> Mime-Version: 1.0 Content-Type: text/plain; format=flowed Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:46901) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fNl1L-0006FV-Qr for guix-devel@gnu.org; Tue, 29 May 2018 16:15:04 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fNl1K-0004c0-SE for guix-devel@gnu.org; Tue, 29 May 2018 16:15:03 -0400 Received: from tobias.gr ([2001:470:cc92::1]:47212) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1fNl1K-0004Zk-FR for guix-devel@gnu.org; Tue, 29 May 2018 16:15:02 -0400 In-reply-to: <20180529200748.GA23835@jasmine.lan> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari Cc: guix-devel@gnu.org Leo, Leo Famulari wrote: > The summary is that a malicious Git remote can execute arbitrary > code on > your machine when you clone from the remote, so please update > ASAP. Thanks for this explicit heads-up! Kind regards, T G-R