forked from git/git
-
Notifications
You must be signed in to change notification settings - Fork 2.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Git for Windows ships with vulnerable Vim #2232
Milestone
Comments
PR? |
dscho
added a commit
to dscho/MSYS2-packages
that referenced
this issue
Jun 17, 2019
We haven't updated quite in a while, and it would appear that our current VIM is susceptible to CVE-2019-12735 (reported via git-for-windows/git#2232). So let's just update to the latest version and get all kinds of fixes/features. Signed-off-by: Johannes Schindelin <[email protected]>
The MSYS2 maintainer indicated that they are busy with some Qt packages. If that takes too long, I'll probably bundle a Git for Windows-only version of the newest |
Alexpux
pushed a commit
to msys2/MSYS2-packages
that referenced
this issue
Jun 18, 2019
We haven't updated quite in a while, and it would appear that our current VIM is susceptible to CVE-2019-12735 (reported via git-for-windows/git#2232). So let's just update to the latest version and get all kinds of fixes/features. Signed-off-by: Johannes Schindelin <[email protected]>
The next version (and the next snapshot) will have this update. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Setup
defaults?
Details
Git for Windows ships with Vim 8.1.1234, which is vulnerable to arbitrary code execution via CVE-2019-12735. See https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md
It should be updated to 8.1.1365 or newer.
The text was updated successfully, but these errors were encountered: