CESA-2017:1576 -- centos 7 mercurialID: oval:org.secpod.oval:def:204535 | Date: (C)2017-07-04 (M)2022-10-10 |
Class: PATCH | Family: unix |
Mercurial is a fast, lightweight source control management system designed for efficient handling of very large distributed projects. Security Fix: * A flaw was found in the way "hg serve --stdio" command in Mercurial handled command-line options. A remote, authenticated attacker could use this flaw to execute arbitrary code on the Mercurial server by using specially crafted command-line options