Software: Apache. PHP/8.3.27 uname -a: Linux pdx1-shared-a4-04 6.6.104-grsec-jammy+ #3 SMP Tue Sep 16 00:28:11 UTC 2025 x86_64 uid=6659440(dh_z2jmpm) gid=2086089(pg10499364) groups=2086089(pg10499364) Safe-mode: OFF (not secure) /usr/share/doc/git/RelNotes/ drwxr-xr-x | |
| Viewing file: Select action/file-type: Git v2.7.6 Release Notes ======================== Fixes since v2.7.5 ------------------ * A "ssh://..." URL can result in a "ssh" command line with a hostname that begins with a dash "-", which would cause the "ssh" command to instead (mis)treat it as an option. This is now prevented by forbidding such a hostname (which will not be necessary in the real world). * Similarly, when GIT_PROXY_COMMAND is configured, the command is run with host and port that are parsed out from "ssh://..." URL; a poorly written GIT_PROXY_COMMAND could be tricked into treating a string that begins with a dash "-". This is now prevented by forbidding such a hostname and port number (again, which will not be necessary in the real world). * In the same spirit, a repository name that begins with a dash "-" is also forbidden now. Credits go to Brian Neel at GitLab, Joern Schneeweisz of Recurity Labs and Jeff King at GitHub. |
:: Command execute :: | |
--[ c99shell v. 2.5 [PHP 8 Update] [24.05.2025] | Generation time: 0.0105 ]-- |