Package        : mercurial
Version        : 3.1.2-2+deb8u7
CVE ID         : CVE-2019-3902
Debian Bug     : #927674

It was discovered that there was a path traversal vulnerability in
the "mercurial" distributed revision version control system.

Symbolic links and subrepositories could be used defeat Mercurial's
path-checking logic and write files outside the repository root.

For Debian 8 "Jessie", this issue has been fixed in mercurial version
3.1.2-2+deb8u7.

We recommend that you upgrade your mercurial packages.


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

Debian LTS: DLA-1764-1: mercurial security update

April 25, 2019
It was discovered that there was a path traversal vulnerability in the "mercurial" distributed revision version control system

Summary

For Debian 8 "Jessie", this issue has been fixed in mercurial version
3.1.2-2+deb8u7.

We recommend that you upgrade your mercurial packages.


Regards,

- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
Package : mercurial
Version : 3.1.2-2+deb8u7
CVE ID : CVE-2019-3902
Debian Bug : #927674

Related News