Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:0880-1

Опубликовано: 27 июн. 2020
Источник: suse-cvrf

Описание

Security update for mercurial

This update for mercurial fixes the following issues:

Security issue fixed:

  • CVE-2019-3902: Fixed incorrect patch-checking with symlinks and subrepos (bsc#1133035).

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.2
mercurial-4.5.2-lp152.7.3.1
mercurial-lang-4.5.2-lp152.7.3.1

Описание

A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.


Затронутые продукты
openSUSE Leap 15.2:mercurial-4.5.2-lp152.7.3.1
openSUSE Leap 15.2:mercurial-lang-4.5.2-lp152.7.3.1

Ссылки