Apple has released a new version of its Xcode development tool to patch two critical vulnerabilities in the Git source code management client.
The Git vulnerabilities, CVE‑2016‑2324 and CVE‑2016‑2315, have been known since mid-March and can be exploited when cloning a repository with a specially crafted file structure. This allows attackers to execute malicious code on systems where such cloning operations were initiated.
Xcode is an integrated development environment (IDE) used by a large number of developers to write applications for OS X and iOS. It includes a package called the OS X Command Line Tools for Xcode that contains the open-source Git client.
To read this article in full or to leave a comment, please click here
Source: COMPUTER WORLD