Re: [oss-security] CVE Request: cgit directory traversal

2013-05-27 Thread Jason A. Donenfeld
On Mon, May 27, 2013 at 2:30 PM, Jan Lieskovsky wrote: > Can you provide a patch that would apply against v0.9.1 version too? Or > would this be just problem of master branch code? I could, but you'd be much better off just upgrading to v0.9.2. ___ CGit

Re: [oss-security] CVE Request: cgit directory traversal

2013-05-27 Thread Jason A. Donenfeld
Hi Kurt, This issue has now been fixed with CGit v0.9.2: The announcement may be read here: http://lists.zx2c4.com/pipermail/cgit/2013-May/001394.html Jason ___ CGit mailing list CGit@lists.zx2c4.com http://lists.zx2c4.com/mailman/listinfo/cgit