Home My Page Projects Site Admin
Summary Activity Tracker Lists Docs News SCM

Forum: git client vulnerability on windows and mac

Posted by: Matthieu Imbert
Date: 2015-01-06 12:34
Summary: git client vulnerability on windows and mac
Project: Site Admin


Windows and Mac users should check the versions of their git clients, as security issue CVE-2014-9390 was recently discovered.

It affects git and mercurial clients on case-insensitive filesystems (most commonly windows and mac).

See http://security.stackexchange.com/questions/76588/how-does-cve-2014-9390-affect-me for an explanation.

To put things into perspective, the impact of this security issue is actually quite low since cloning from a git/mercurial repository is usually followed by executing a makefile, so in any case, code is executed, this vulnerability only changes the time of execution.

We have conducted an audit of all git repositories on the inria forge, there is currently no repository with suspicious case conflicting .git repositories versionned.
Latest News

AWstats deactivation

Matthieu Imbert - 2018-11-22 13:20 -

git-annex available on the forge

Matthieu Imbert - 2017-07-04 13:39 -
Monitor Forum | Start New Thread Start New Thread
Topic Topic Starter Replies Last Post
Welcome to git-client-vulnerability-on-windows-and-macMatthieu Imbert02015-01-06 12:34