Roll20 uses cookies to improve your experience on our site. Cookies enable you to enjoy certain features, social sharing functionality, and tailor message and display ads to your interests on our site and others. They also help us understand how our site is being used. By continuing to use our site, you consent to our use of cookies. Update your cookie preferences .
×
Create a free account

Git client vulnerability announced -- update recommended

1419100199
Dan W.
Sheet Author
Hey folks, just saw this announced from two days ago. Did a quick search of the forums for 'vulnerability' and saw nothing sorry if this is a duplicate. <a href="https://github.com/blog/1938-git-client-vulnerabil" rel="nofollow">https://github.com/blog/1938-git-client-vulnerabil</a>... This affects both Windows and Mac for both git clients and GitHub for Mac or GitHub for Windows because it exploits the way a git repository tree is formed, see link for details. GitHub looks to be scanning for repo's that take advantage of this and blocking them, but thought I should mention it. Probably not urgent unless you are in the habit of downloading repos and joining projects.
1419104162
Lithl
Pro
Sheet Author
API Scripter
While it's definitely a good idea to update your vulnerable software, I'd like to reiterate a point made in the linked blog post: repositories hosted on github.com cannot contain tree structures which exploit this problem, because GitHub is fixing it on their end when it comes to the repositories themselves. If all git repositories you are touching are being hosted on github.com (as I suspect most users here on Roll20 are, for character sheets), there is no need to panic. Updating your software version is still recommended, though!
As Brian points out, this shouldn't be an issue for anyone participating in character sheet creation since we use github, but all the same I've updated my local git versions anyway just to be safe :-)