-
Wed Oct 31 2018 Marcel Plch <mplch@redhat.com> - 2.9.3-8
- Edit wording in changelog
- Related: CVE-2018-17456
-
Tue Oct 30 2018 Marcel Plch <mplch@redhat.com> - 2.9.3-7
- Add fsck fix missing in previous commit
- Resolves: CVE-2018-17456
-
Wed Oct 24 2018 Marcel Plch <mplch@redhat.com> - 2.9.3-6
- Patch for arbitrary code execution via .gitmodules (CVE-2018-17456)
- Original backport by Jonathan Nieder for Debian
- Original backport: https://repo.or.cz/git/debian.git/commit/63af93488dc4066a937aaa130b35dff398db2368
- Original tests: https://repo.or.cz/git/debian.git/commit/2b4d394113d28a856f2cf375d0cbef3806e9a2c8
- Resolves: rhbz#1638265
-
Fri Aug 24 2018 Pavel Cahyna <pcahyna@redhat.com> - 2.9.3-5
- rebuild for all arches (#1618394)
-
Thu Jun 21 2018 Sebastian Kisela <skisela@redhat.com> - 2.9.3-4
- Backport the fix for CVE-2018-11235 and CVE-2018-11233.
- Thanks to Jonathan Nieder <jrnieder@gmail.com> for backporting to 2.11.x
and to Steve Beattie <sbeattie@ubuntu.com> for backporting to 2.7.x.
-
Fri Aug 11 2017 Petr Stodulka <pstodulk@redhat.com> - 2.9.3-3
- prevent command injection via malicious ssh URLs
- dissalow repo names beginning with dash
Resolves: CVE-2017-8386 CVE-2017-1000117
-
Fri Oct 14 2016 Petr Stodulka <pstodulk@redhat.com> - 2.9.3-2
- fix infinite loop of "git ls-tree" on broken symlink
Resolves: #1204191
-
Mon Oct 10 2016 Petr Stodulka <pstodulk@redhat.com> - 2.9.3-1
- Rebase to 2.9.3
- add control of GSSAPI credential delegation to enable HTTP(S)-SSO
authentication
Resolves: #1359176 #1382708
-
Mon Aug 08 2016 Petr Stodulka <pstodulk@redhat.com> - 2.9.2-5
- fix service file to use rh-git29 instead of native git
- fix desktop file - changed names & paths inside the file,
use scl rh-git29 instead of native git, change filename
and path of the file to system directory instead of scl
- *git-daemon: xinetd.d: use system directory and added prefix to the filename
- *git-gitweb: store git.conf to directory of httpd24 sclm add scl prefix
to the filename and correct paths inside the file to correct rh-git29
www directory
- fix doubled path for emacs-sitelisp files
- build and link files with httpd24-libcurl
Resolves: #1345897
-
Fri Aug 05 2016 Petr Stodulka <pstodulk@redhat.com> - 2.9.2-4
- fix deprecated "vendor" tag for RHEL-6 (it was used for older
RHEL systems)