Just installing git from Homebrew or MacPorts is not enough to be safe from this remote code execution.
Just installing git from Homebrew or MacPorts is not enough to be safe from this remote code execution.
That said, any program that invokes /usr/bin/git directly instead of /usr/bin/env git would still be vulnerable.
It's not as big of a problem as the article makes it out to be so long as you install a newer version of git.
If you're really concerned, the filesystem restrictions mentioned can be bypassed by booting into safe mode. Though it's still not a good idea to mess with the default program installations since Apple may depend on that particular version of git for some program.
If it is there without XCLT, then anyone reading this is more than capable of removing it, and dealing with anything that subsequently can't find it.