Package : mercurial Version : 2.2.2-4+deb7u6 CVE ID : CVE-2017-17458 A vulnerability was found in the Mercurial version control system which could lead to remote arbitrary code execution. CVE-2017-17458 A specially malformed Mercurial repository could cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the parent repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically. For Debian 7 "Wheezy", these problems have been fixed in version 2.2.2-4+deb7u6. We recommend that you upgrade your mercurial packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment:
signature.asc
Description: PGP signature