[openstack-dev] Git client vulnerability

2014-12-19 Thread Dr. Jens Rosenboom
As this may affect a reasonable percentage of the target audience, I would like to make everyone aware of https://github.com/blog/1938-vulnerability-announced-update-your-git-clients While github.com claim to have patched their servers, people using other repos may want to be extra cautious.

Re: [openstack-dev] Git client vulnerability

2014-12-19 Thread Jeremy Stanley
On 2014-12-19 13:35:06 +0100 (+0100), Dr. Jens Rosenboom wrote: [...] While github.com claim to have patched their servers, people using other repos may want to be extra cautious. Please re-read that advisory[1]. GitHub's _servers_ were not affected as this is a client-side vulnerability. What

Re: [openstack-dev] Git client vulnerability

2014-12-19 Thread Louis Taylor
On Fri, Dec 19, 2014 at 01:19:48PM +, Jeremy Stanley wrote: Please re-read that advisory[1]. GitHub's _servers_ were not affected as this is a client-side vulnerability. What GitHub did was release fixed versions of their GitHub for Windows and GitHub for Mac _client_ tools. Github's

Re: [openstack-dev] Git client vulnerability

2014-12-19 Thread Jeremy Stanley
On 2014-12-19 13:34:06 + (+), Louis Taylor wrote: On Fri, Dec 19, 2014 at 01:19:48PM +, Jeremy Stanley wrote: Please re-read that advisory[1]. GitHub's _servers_ were not affected as this is a client-side vulnerability. What GitHub did was release fixed versions of their GitHub