Описание
Security update for mercurial
This update for mercurial fixes the following issues:
- CVE-2017-9462: Fix the arbitrary code exec by remote users via 'hg serve --stdio' (boo#1043063)
Список пакетов
openSUSE Leap 42.2
mercurial-3.8.3-2.5.1
mercurial-lang-3.8.3-2.5.1
Ссылки
- E-Mail link for openSUSE-SU-2017:1572-1
- SUSE Security Ratings
Описание
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
Затронутые продукты
openSUSE Leap 42.2:mercurial-3.8.3-2.5.1
openSUSE Leap 42.2:mercurial-lang-3.8.3-2.5.1
Ссылки
- CVE-2017-9462
- SUSE Bug 1043063