MinGit for Windows 2.45.2(2)
mjcheetham
released this
14 Jan 18:14
·
7879 commits
to main
since this release
Changes since Git for Windows v2.45.2 (June 3rd 2024)
New Features
- Comes with Git Credential Manager v2.6.1, addressing CVE-2024-50338.
Bug Fixes
- CVE-2024-50338: Git Credential Manager can be tricked to exfiltrate credentials for a trusted site to an untrusted site. Since the URLs needed for such an attack look suspicious, this usually requires a recursive clone or fetch.
- CVE-2024-50349: When prompting the user for a password in the terminal, Git does not neutralize control characters.
- CVE-2024-52005: The sideband channel does not neutralize control characters.
- CVE-2024-52006: Similar to CVE-2020-5260, affecting credential helpers that interpret Carriage Returns as newlines.
Filename | SHA-256 |
---|---|
MinGit-2.45.2.2-64-bit.zip | 93ce6daa762cd82b7558162b7caee6fc60dc6e630b0b4b1a15307e7480a0c64d |
MinGit-2.45.2.2-32-bit.zip | f1b3272a303435c89e60645e2f1460b9c6679032f6ff15b21713b7d44044dd3e |
MinGit-2.45.2.2-busybox-64-bit.zip | df3c7364d04e9f208d560f9f18552c4d3f7b59a987bc0a4aaa2b92263ade9221 |
MinGit-2.45.2.2-busybox-32-bit.zip | cb19c568df462288128ed17467593506a1e63de30914bd8507c236e1a78b3b18 |