On Tue, Mar 15, 2016 at 07:42:53PM -0400, Leo Famulari wrote: > There is an update for git and git-manpages on master. Please update > your installations, both clients and servers! > > http://seclists.org/oss-sec/2016/q1/645
It turns out that although the bugs [0] had been publicly disclosed, the Git maintainers had not yet released a version with the fix. Version 2.7.4 was the bug fix release [1]. Please update your installations! [0] https://cve.mitre.org/cgi-bin/cvename.cgi?name=2016-2315 https://cve.mitre.org/cgi-bin/cvename.cgi?name=2016-2324 [1] https://git.kernel.org/cgit/git/git.git/commit/?h=v2.7.4&id=937978e0f3e750d917768c77665d5f8cfbd802b6