CVE-2017-12976: A hostname starting with a dash would get passed to ssh and be treated as an option. This could be used by an attacker who provides a crafted repository url to cause the victim to execute arbitrary code via -oProxyCommand.

Fixed in git-annex 6.20170818

This is related to a git security hole, CVE-2017-1000117.

[[!meta Error: Can't locate Date/Parse.pm in @INC (you may need to install the Date::Parse module) (@INC entries checked: /etc/perl /usr/local/lib/i386-linux-gnu/perl/5.40.1 /usr/local/share/perl/5.40.1 /usr/lib/i386-linux-gnu/perl5/5.40 /usr/share/perl5 /usr/lib/i386-linux-gnu/perl-base /usr/lib/i386-linux-gnu/perl/5.40 /usr/share/perl/5.40 /usr/local/lib/site_perl) at (eval 22602) line 1. BEGIN failed--compilation aborted at (eval 22602) line 1. ]]