MGASA-2015-0129

Source
https://advisories.mageia.org/MGASA-2015-0129.html
Import Source
https://advisories.mageia.org/MGASA-2015-0129.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0129
Related
Published
2015-04-03T13:11:23Z
Modified
2015-04-03T12:59:38Z
Summary
Updated mercurial packages fix CVE-2014-9462
Details

Updated mercurial packages fix security vulnerability:

The mercurial source code management system suffers from a code-injection flaw due to insufficient shell quoting in sshpeer._validaterepo() (CVE-2014-9462).

References
Credits

Affected packages

Mageia:4 / mercurial

Package

Name
mercurial
Purl
pkg:rpm/mageia/mercurial?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.2-3.1.mga4

Ecosystem specific

{
    "section": "core"
}