Debian: DSA-5332-1: git security update
Summary
This update includes two changes of behavior that may affect certain setup:
- It stops when directory traversal changes ownership from the current
user while looking for a top-level git directory, a user could make an
exception by using the new safe.directory configuration.
- The default of protocol.file.allow has been changed from "always" to
"user".
For the stable distribution (bullseye), these problems have been fixed in
version 1:2.30.2-1+deb11u1.
We recommend that you upgrade your git packages.
For the detailed security status of git please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/git
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/