Debian LTS: DLA-1414-1: mercurial security update
Summary
In Mercurial before 4.1.3, "hg serve --stdio" allows remote
authenticated users to launch the Python debugger, and
consequently execute arbitrary code, by using --debugger as a
repository name.
CVE-2017-17458
In Mercurial before 4.4.1, it is possible that a specially
malformed repository can cause Git subrepositories to run
arbitrary code in the form of a .git/hooks/post-update script
checked into the repository. Typical use of Mercurial prevents
construction of such repositories, but they can be created
programmatically.
CVE-2018-1000132
Mercurial version 4.5 and earlier contains a Incorrect Access
Control (CWE-285) vulnerability in Protocol server that can result
in Unauthorized data access. This attack appear to be exploitable
via network connectivity. This vulnerability appears to have been
fixed in 4.5.1.
OVE-20180430-0001
mpatch: be more careful about parsing binary patch data
OVE-20180430-0002
mpatch: protect against underflow i...
Package :mercurial