Re: [fossil-dev] The "ssh://" vulnerability

2017-08-11 Thread Warren Young
On Aug 11, 2017, at 9:41 AM, Richard Hipp wrote: > > I am open to arguments to the contrary, if you feel > differently. It would be an excuse to push out the final SQLite 3.20 version... ___ fossil-dev mailing list fossil-dev@mailinglists.sqlite.org ht

[fossil-dev] The "ssh://" vulnerability

2017-08-11 Thread Richard Hipp
There were coordinated releases today of Git, Hg, and SVN to patch a vulnerability associated with the use of "ssh://" in those systems. If the hostname or some other property of the URL could be manipulated to begin with a "-" character, then the constructed "ssh" command would understand the name