Fixes CVE-2017-9462.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-b154ff2892 2017-06-26 19:07:17.381365 --------------------------------------------------------------------------------Name : mercurial Product : Fedora 24 Version : 3.7.3 Release : 2.fc24 URL : Summary : Mercurial -- a distributed SCM Description : Mercurial is a fast, lightweight source control management system designed for efficient handling of very large distributed projects. Quick start: https://wiki.mercurial-scm.org/QuickStart Tutorial: Extensions: --------------------------------------------------------------------------------Update Information: Fixes CVE-2017-9462. --------------------------------------------------------------------------------References: [ 1 ] Bug #1459485 - CVE-2017-9462 mercurial: Python debugger accessible to authorized users [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1459485 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mercurial' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Jann Horn discovered that the source package integrity verification in dpkg-source can be bypassed via a specially crafted Debian source control file (.dsc). Note that this flaw only affects extraction of local Debian source packages via dpkg-source but not the installation of . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3217-1
Get the latest Linux and open source security news straight to your inbox.