UbuntuUpdates.org

Package "mercurial"

Name: mercurial

Description:

easy-to-use, scalable distributed version control system

Latest version: 2.0.2-1ubuntu1.2
Release: precise (12.04)
Level: updates
Repository: universe
Homepage: http://mercurial.selenic.com/

Links


Download "mercurial"


Other versions of "mercurial" in Precise

Repository Area Version
base universe 2.0.2-1ubuntu1
security universe 2.0.2-1ubuntu1.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.0.2-1ubuntu1.2 2015-06-17 22:06:47 UTC

  mercurial (2.0.2-1ubuntu1.2) precise-security; urgency=medium

  [ Jamie Strandboge ]
  * SECURITY UPDATE: fix for improperly handling case-insensitive paths on
    Windows and OS X clients
    - http://selenic.com/repo/hg-stable/rev/885bd7c5c7e3
    - http://selenic.com/repo/hg-stable/rev/c02a05cc6f5e
    - http://selenic.com/repo/hg-stable/rev/6dad422ecc5a
    - CVE-2014-9390
    - LP: #1404035

  [ Marc Deslauriers ]
  * SECURITY UPDATE: arbitrary command exection via crafted repository
    name in a clone command
    - d/p/from_upstream__sshpeer_more_thorough_shell_quoting.patch: add
      more thorough shell quoting to mercurial/sshrepo.py.
    - CVE-2014-9462

 -- Marc Deslauriers <email address hidden> Wed, 17 Jun 2015 13:27:17 -0400

CVE-2014-9390 arbitrary command execution vulnerability on case-insensitive file systems
CVE-2014-9462 The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name i



About   -   Send Feedback to @ubuntu_updates