Joined: 12 May 2004
|Posted: Wed Dec 07, 2016 2:26 pm Post subject: [ GLSA 201612-19 ] Mercurial
|Gentoo Linux Security Advisory
Title: Mercurial: Multiple vulnerabilities (GLSA 201612-19)
Date: December 07, 2016
Bug(s): #533008, #544332, #578546, #582238
Multiple vulnerabilities have been found in Mercurial, the worst of
which could lead to the remote execution of arbitrary code.
Mercurial is a distributed source control management system.
Vulnerable: < 3.8.4
Unaffected: >= 3.8.4
Architectures: All supported architectures
Multiple vulnerabilities have been discovered in Mercurial. Please
review the CVE identifier and bug reports referenced for details.
A remote attacker could possibly execute arbitrary code with the
privileges of the process.
There is no known workaround at this time.
All mercurial users should upgrade to the latest version:
|# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-vcs/mercurial-3.8.4"