Описание
Security update for mercurial
Mercurial was updated to fix a command injection via sshpeer._validaterepo() (CVE-2014-9462, bnc#923070):
Список пакетов
SUSE Linux Enterprise Software Development Kit 12
mercurial-2.8.2-3.1
Ссылки
- Link for SUSE-SU-2015:0836-1
- E-Mail link for SUSE-SU-2015:0836-1
- SUSE Security Ratings
- SUSE Bug 923070
- SUSE CVE CVE-2014-9462 page
Описание
The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows remote attackers to execute arbitrary commands via a crafted repository name in a clone command.
Затронутые продукты
SUSE Linux Enterprise Software Development Kit 12:mercurial-2.8.2-3.1
Ссылки
- CVE-2014-9462
- SUSE Bug 923070