CVE-2017-12976: A hostname starting with a dash would get passed to ssh and be treated as
an option. This could be used by an attacker who provides a crafted
repository url to cause the victim to execute arbitrary code via
-oProxyCommand
.
Fixed in git-annex 6.20170818
This is related to a git security hole, CVE-2017-1000117.
[[!meta Error: Can't locate Date/Parse.pm in @INC (you may need to install the Date::Parse module) (@INC contains: /etc/perl /usr/local/lib/arm-linux-gnueabi/perl/5.28.1 /usr/local/share/perl/5.28.1 /usr/lib/arm-linux-gnueabi/perl5/5.28 /usr/share/perl5 /usr/lib/arm-linux-gnueabi/perl/5.28 /usr/share/perl/5.28 /usr/local/lib/site_perl /usr/lib/arm-linux-gnueabi/perl-base) at (eval 18820) line 1. BEGIN failed--compilation aborted at (eval 18820) line 1. ]]