Article 2Z0CY Source-code management system security updates

Source-code management system security updates

by
corbet
from LWN.net on (#2Z0CY)
It turns out that even rather different source-code management systems canhave similar vulnerabilities. This can be seen in the Git v2.14.1,Mercurial 4.3, andSubversion 1.9.7 releases (plus updates ofolder releases). In each case, it's possible to provide a maliciousrepository URLthat ends up executing code; these URLs can be buried outof sight in existing repositories. Updating would be a good idea,regardless of which system you use.
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments