GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sun Sep 24, 2017 7:26 pm Post subject: [ GLSA 201709-18 ] Mercurial |
|
|
Gentoo Linux Security Advisory
Title: Mercurial: Multiple vulnerabilities (GLSA 201709-18)
Severity: normal
Exploitable: remote
Date: 2017-09-24
Bug(s): #621068, #627484
ID: 201709-18
Synopsis
Multiple vulnerabilities have been found in Mercurial, the worst of
which could lead to the remote execution of arbitrary code.
Background
Mercurial is a distributed source control management system.
Affected Packages
Package: dev-vcs/mercurial
Vulnerable: < 4.3
Unaffected: >= 4.3
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Mercurial. Please
review the referenced CVE identifiers for details.
Impact
A remote attacker could possibly execute arbitrary code with the
privileges of the process.
Workaround
There is no known workaround at this time.
Resolution
All Mercurial users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-vcs/mercurial-4.3"
|
References
CVE-2017-1000115
CVE-2017-1000116
CVE-2017-9462
|
|