Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, as long as "dpkg -l git" shows that you have package version 1:2.1.4-2.1+deb8u2 or later. Debian backported the fixes:

  git (1:2.1.4-2.1+deb8u2) jessie-security; urgency=high
  
    * Non-maintainer upload by the Security Team.
    * Fix remote code execution via buffer overflows (CVE-2016-2315, CVE-2016-2324) (Closes: #818318)
  
   -- Salvatore Bonaccorso <carnil@debian.org>  Fri, 18 Mar 2016 06:20:38 +0100
The Debian Changelog (where you find this stuff out) is linked from the package page at https://packages.debian.org/jessie/git (on the right hand side under Debian Resources) or you can look at /usr/share/doc/git/changelog.Debian.gz on your system.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: