Debian LTS: DLA-1072-1: mercurial security update
Summary
CVE-2017-1000115
Mercurial's symlink auditing was incomplete prior to 4.3, and
could be abused to write to files outside the repository.
CVE-2017-1000116
Mercurial was not sanitizing hostnames passed to ssh, allowing
shell injection attacks on clients by specifying a hostname
starting with -oProxyCommand. This vulnerability is similar to
those in Git (CVE-2017-1000117) and Subversion (CVE-2017-9800).
For Debian 7 "Wheezy", these problems have been fixed in version
2.2.2-4+deb7u5.
We recommend that you upgrade your mercurial packages.
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS