Updated mercurial package fixes security vulnerabilities
Publication date: 07 Sep 2017Modification date: 07 Sep 2017
Type: security
Affected Mageia releases : 5
CVE: CVE-2017-1000115 , CVE-2017-1000116
Description
Mercurial was not sanitizing hostnames passed to ssh, allowing shell injection attacks by specifying a hostname starting with -oProxyCommand.
References
SRPMS
5/core
- mercurial-3.1.1-5.5.mga5