Advisories ยป MGASA-2017-0331

Updated mercurial package fixes security vulnerabilities

Publication date: 07 Sep 2017
Modification date: 07 Sep 2017
Type: security
Affected Mageia releases : 5
CVE: CVE-2017-1000115 , CVE-2017-1000116

Description

Mercurial was not sanitizing hostnames passed to ssh, allowing shell
injection attacks by specifying a hostname starting with -oProxyCommand.
                

References

SRPMS

5/core