[ Marc Deslauriers ]
* SECURITY UPDATE: arbitrary command exection via crafted repository
name in a clone command
- d/p/from_upstream__sshpeer_more_thorough_shell_quoting.patch: add
more thorough shell quoting to mercurial/sshpeer.py.
- CVE-2014-9462
* debian/patches/fix_ftbfs_patchbomb_test.patch: fix patchbomb test.
-- Marc Deslauriers <email address hidden> Wed, 17 Jun 2015 10:51:42 -0400
This bug was fixed in the package mercurial - 2.8.2-1ubuntu1.3
---------------
mercurial (2.8.2-1ubuntu1.3) trusty-security; urgency=medium
[ Jamie Strandboge ] selenic. com/repo/ hg-stable/ rev/885bd7c5c7e 3 selenic. com/repo/ hg-stable/ rev/c02a05cc6f5 e selenic. com/repo/ hg-stable/ rev/6dad422ecc5 a
* SECURITY UPDATE: fix for improperly handling case-insensitive paths on
Windows and OS X clients
- http://
- http://
- http://
- CVE-2014-9390
- LP: #1404035
[ Marc Deslauriers ] upstream_ _sshpeer_ more_thorough_ shell_quoting. patch: add sshpeer. py. patches/ fix_ftbfs_ patchbomb_ test.patch: fix patchbomb test.
* SECURITY UPDATE: arbitrary command exection via crafted repository
name in a clone command
- d/p/from_
more thorough shell quoting to mercurial/
- CVE-2014-9462
* debian/
-- Marc Deslauriers <email address hidden> Wed, 17 Jun 2015 10:51:42 -0400