Quoting from 
https://github.com/blog/1938-vulnerability-announced-update-your-git-clients

"""
A critical Git security vulnerability has been announced today, affecting all 
versions of the official Git client and all related software that interacts 
with Git repositories, including GitHub for Windows and GitHub for Mac. Because 
this is a client-side only vulnerability, github.com and GitHub Enterprise are 
not directly affected.

The vulnerability concerns Git and Git-compatible clients that access Git 
repositories in a case-insensitive or case-normalizing filesystem. An attacker 
can craft a malicious Git tree that will cause Git to overwrite its own 
.git/config file when cloning or checking out a repository, leading to 
arbitrary command execution in the client machine. Git clients running on OS X 
(HFS+) or any version of Microsoft Windows (NTFS, FAT) are exploitable through 
this vulnerability. Linux clients are not affected if they run in a 
case-sensitive filesystem.

We strongly encourage all users of GitHub and GitHub Enterprise to update their 
Git clients as soon as possible, and to be particularly careful when cloning or 
accessing Git repositories hosted on unsafe or untrusted hosts.
"""

The official Git release post: 
http://article.gmane.org/gmane.linux.kernel/1853266

-Dave

Reply via email to