Описание
Security update for mercurial
mercurial was updated to fix a potential command injection via sshpeer._validaterepo() (CVE-2014-9462)
Security Issues:
* CVE-2014-9462
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9462>
Список пакетов
SUSE Linux Enterprise Software Development Kit 11 SP3
mercurial-2.3.2-0.9.2
Ссылки
- Link for SUSE-SU-2015:0817-1
- E-Mail link for SUSE-SU-2015:0817-1
- SUSE Security Ratings
- SUSE Bug 923070
- SUSE CVE CVE-2014-9462 page
Описание
The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.
Затронутые продукты
SUSE Linux Enterprise Software Development Kit 11 SP3:mercurial-2.3.2-0.9.2
Ссылки
- CVE-2014-9462
- SUSE Bug 923070