Re: [openstack-dev] Git client vulnerability

2014-12-19 Thread Jeremy Stanley
On 2014-12-19 13:34:06 + (+), Louis Taylor wrote: > On Fri, Dec 19, 2014 at 01:19:48PM +, Jeremy Stanley wrote: > > Please re-read that advisory[1]. GitHub's _servers_ were not > > affected as this is a client-side vulnerability. What GitHub did was > > release fixed versions of their "

Re: [openstack-dev] Git client vulnerability

2014-12-19 Thread Louis Taylor
On Fri, Dec 19, 2014 at 01:19:48PM +, Jeremy Stanley wrote: > Please re-read that advisory[1]. GitHub's _servers_ were not > affected as this is a client-side vulnerability. What GitHub did was > release fixed versions of their "GitHub for Windows" and "GitHub for > Mac" _client_ tools. Github

Re: [openstack-dev] Git client vulnerability

2014-12-19 Thread Jeremy Stanley
On 2014-12-19 13:35:06 +0100 (+0100), Dr. Jens Rosenboom wrote: [...] > While github.com claim to have patched their servers, people using > other repos may want to be extra cautious. Please re-read that advisory[1]. GitHub's _servers_ were not affected as this is a client-side vulnerability. What

[openstack-dev] Git client vulnerability

2014-12-19 Thread Dr. Jens Rosenboom
As this may affect a reasonable percentage of the target audience, I would like to make everyone aware of https://github.com/blog/1938-vulnerability-announced-update-your-git-clients While github.com claim to have patched their servers, people using other repos may want to be extra cautious.