<feed xmlns='http://www.w3.org/2005/Atom'>
<title>git, branch v1.6.6.3</title>
<subtitle>Mirror of https://git.kernel.org/pub/scm/git/git.git/
</subtitle>
<id>https://www.git.shady.money/git/atom?h=v1.6.6.3</id>
<link rel='self' href='https://www.git.shady.money/git/atom?h=v1.6.6.3'/>
<link rel='alternate' type='text/html' href='https://www.git.shady.money/git/'/>
<updated>2010-12-15T19:32:57Z</updated>
<entry>
<title>Git 1.6.6.3</title>
<updated>2010-12-15T19:32:57Z</updated>
<author>
<name>Junio C Hamano</name>
<email>gitster@pobox.com</email>
</author>
<published>2010-12-15T19:32:57Z</published>
<link rel='alternate' type='text/html' href='https://www.git.shady.money/git/commit/?id=abf411e28d9df669b0e690578a1eb95c0bd29847'/>
<id>urn:sha1:abf411e28d9df669b0e690578a1eb95c0bd29847</id>
<content type='text'>
Signed-off-by: Junio C Hamano &lt;gitster@pobox.com&gt;
</content>
</entry>
<entry>
<title>Git 1.6.5.9</title>
<updated>2010-12-15T19:27:41Z</updated>
<author>
<name>Junio C Hamano</name>
<email>gitster@pobox.com</email>
</author>
<published>2010-12-15T19:27:41Z</published>
<link rel='alternate' type='text/html' href='https://www.git.shady.money/git/commit/?id=ec82874ad47627a44b6b22a6645551a214293711'/>
<id>urn:sha1:ec82874ad47627a44b6b22a6645551a214293711</id>
<content type='text'>
Signed-off-by: Junio C Hamano &lt;gitster@pobox.com&gt;
</content>
</entry>
<entry>
<title>Git 1.6.4.5</title>
<updated>2010-12-15T19:19:11Z</updated>
<author>
<name>Junio C Hamano</name>
<email>gitster@pobox.com</email>
</author>
<published>2010-12-15T19:19:11Z</published>
<link rel='alternate' type='text/html' href='https://www.git.shady.money/git/commit/?id=88fcc52e4468d5dfef4f50d2bdee4b168a855368'/>
<id>urn:sha1:88fcc52e4468d5dfef4f50d2bdee4b168a855368</id>
<content type='text'>
Signed-off-by: Junio C Hamano &lt;gitster@pobox.com&gt;
</content>
</entry>
<entry>
<title>gitweb: Introduce esc_attr to escape attributes of HTML elements</title>
<updated>2010-12-15T19:16:31Z</updated>
<author>
<name>Jakub Narebski</name>
<email>jnareb@gmail.com</email>
</author>
<published>2010-12-14T23:34:01Z</published>
<link rel='alternate' type='text/html' href='https://www.git.shady.money/git/commit/?id=3017ed62f47ce14a959e2d315c434d4980cf4243'/>
<id>urn:sha1:3017ed62f47ce14a959e2d315c434d4980cf4243</id>
<content type='text'>
It is needed only to escape attributes of handcrafted HTML elements,
and not those generated using CGI.pm subroutines / methods for HTML
generation.

While at it, add esc_url and esc_html where needed, and prefer to use
CGI.pm HTML generating methods than handcrafted HTML code.  Most of
those are probably unnecessary (could be exploited only by person with
write access to gitweb config, or at least access to the repository).

This fixes CVE-2010-3906

Reported-by: Emanuele Gentili &lt;e.gentili@tigersecurity.it&gt;
Helped-by: John 'Warthog9' Hawley &lt;warthog9@kernel.org&gt;
Helped-by: Jonathan Nieder &lt;jrnieder@gmail.com&gt;
Signed-off-by: Jakub Narebski &lt;jnareb@gmail.com&gt;
Signed-off-by: Junio C Hamano &lt;gitster@pobox.com&gt;
</content>
</entry>
<entry>
<title>Merge branch 'maint-1.6.5' into maint-1.6.6</title>
<updated>2010-07-26T04:52:29Z</updated>
<author>
<name>Junio C Hamano</name>
<email>gitster@pobox.com</email>
</author>
<published>2010-07-26T04:52:29Z</published>
<link rel='alternate' type='text/html' href='https://www.git.shady.money/git/commit/?id=ad336054068074ed614d0bb54bb169e5263499d7'/>
<id>urn:sha1:ad336054068074ed614d0bb54bb169e5263499d7</id>
<content type='text'>
* maint-1.6.5:
  request-pull.txt: Document -p option
  Check size of path buffer before writing into it
  rev-parse: fix --parse-opt --keep-dashdash --stop-at-non-option
</content>
</entry>
<entry>
<title>request-pull.txt: Document -p option</title>
<updated>2010-07-26T04:52:19Z</updated>
<author>
<name>Stephen Boyd</name>
<email>bebarino@gmail.com</email>
</author>
<published>2010-07-23T16:31:27Z</published>
<link rel='alternate' type='text/html' href='https://www.git.shady.money/git/commit/?id=d8e3ac7e7264863544c95069024f1cbaedb5db3d'/>
<id>urn:sha1:d8e3ac7e7264863544c95069024f1cbaedb5db3d</id>
<content type='text'>
Signed-off-by: Stephen Boyd &lt;bebarino@gmail.com&gt;
Signed-off-by: Junio C Hamano &lt;gitster@pobox.com&gt;
</content>
</entry>
<entry>
<title>Merge branch 'maint-1.6.4' into maint-1.6.5</title>
<updated>2010-07-26T04:51:58Z</updated>
<author>
<name>Junio C Hamano</name>
<email>gitster@pobox.com</email>
</author>
<published>2010-07-26T04:51:58Z</published>
<link rel='alternate' type='text/html' href='https://www.git.shady.money/git/commit/?id=a07b10c8f930e88386d3b7424f25190af554275e'/>
<id>urn:sha1:a07b10c8f930e88386d3b7424f25190af554275e</id>
<content type='text'>
* maint-1.6.4:
  Check size of path buffer before writing into it
  rev-parse: fix --parse-opt --keep-dashdash --stop-at-non-option
</content>
</entry>
<entry>
<title>Check size of path buffer before writing into it</title>
<updated>2010-07-25T17:33:47Z</updated>
<author>
<name>Greg Brockman</name>
<email>gdb@MIT.EDU</email>
</author>
<published>2010-07-20T04:46:21Z</published>
<link rel='alternate' type='text/html' href='https://www.git.shady.money/git/commit/?id=1b0b962d771fb734cbf273f216b487bb58dec7b9'/>
<id>urn:sha1:1b0b962d771fb734cbf273f216b487bb58dec7b9</id>
<content type='text'>
This prevents a buffer overrun that could otherwise be triggered by
creating a file called '.git' with contents

  gitdir: (something really long)

Signed-off-by: Greg Brockman &lt;gdb@mit.edu&gt;
Signed-off-by: Junio C Hamano &lt;gitster@pobox.com&gt;
</content>
</entry>
<entry>
<title>rev-parse: fix --parse-opt --keep-dashdash --stop-at-non-option</title>
<updated>2010-07-07T18:11:50Z</updated>
<author>
<name>Uwe Kleine-König</name>
<email>u.kleine-koenig@pengutronix.de</email>
</author>
<published>2010-07-06T14:46:05Z</published>
<link rel='alternate' type='text/html' href='https://www.git.shady.money/git/commit/?id=29981380d03ffa63765dbeaea53a7ac9e8d6bc4f'/>
<id>urn:sha1:29981380d03ffa63765dbeaea53a7ac9e8d6bc4f</id>
<content type='text'>
The ?: operator has a lower priority than |, so the implicit associativity
made the 6th argument of parse_options be PARSE_OPT_KEEP_DASHDASH if
keep_dashdash was true discarding PARSE_OPT_STOP_AT_NON_OPTION and
PARSE_OPT_SHELL_EVAL.

Signed-off-by: Uwe Kleine-König &lt;u.kleine-koenig@pengutronix.de&gt;
Signed-off-by: Junio C Hamano &lt;gitster@pobox.com&gt;
</content>
</entry>
<entry>
<title>MSVC: Fix build by adding missing termios.h dummy</title>
<updated>2010-04-19T08:28:21Z</updated>
<author>
<name>Johannes Sixt</name>
<email>j6t@kdbg.org</email>
</author>
<published>2010-04-19T07:37:20Z</published>
<link rel='alternate' type='text/html' href='https://www.git.shady.money/git/commit/?id=b75686455c0524f167b6a878c124df40db34b325'/>
<id>urn:sha1:b75686455c0524f167b6a878c124df40db34b325</id>
<content type='text'>
A use of this header file was introduced in eb80042 (Add missing #include
to support TIOCGWINSZ on Solaris, 2010-01-11).

Signed-off-by: Johannes Sixt &lt;j6t@kdbg.org&gt;
Signed-off-by: Junio C Hamano &lt;gitster@pobox.com&gt;
</content>
</entry>
</feed>
