Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/mono/libgit2.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorEdward Thomson <ethomson@edwardthomson.com>2019-08-05 02:11:54 +0300
committerEdward Thomson <ethomson@edwardthomson.com>2019-08-05 02:11:54 +0300
commitee6ebcc90a625d5ae252cfd2c3986c389237547f (patch)
treeb3ee9e55f9e704ce5f7788555168c4984085a942
parent3316f666566f768eb8aa8de521a5262524dc3424 (diff)
v0.28.3: update changelog for security release
-rw-r--r--docs/changelog.md15
1 files changed, 15 insertions, 0 deletions
diff --git a/docs/changelog.md b/docs/changelog.md
index d6ad2a9ce..6166f5cac 100644
--- a/docs/changelog.md
+++ b/docs/changelog.md
@@ -1,3 +1,18 @@
+v0.28.3
+-------
+
+This is a security release fixing the following issues:
+
+* A carefully constructed commit object with a very large number
+ of parents may lead to potential out-of-bounds writes or
+ potential denial of service.
+
+* The ProgramData configuration file is always read for compatibility
+ with Git for Windows and Portable Git installations. The ProgramData
+ location is not necessarily writable only by administrators, so we
+ now ensure that the configuration file is owned by the administrator
+ or the current user.
+
v0.28.2
-------