Information on source package mercurial

Available versions

ReleaseVersion
jessie3.1.2-2+deb8u7
stretch4.0-1+deb9u2
buster4.8.2-1+deb10u1
bullseye5.6.1-4
bookworm6.3.2-1
trixie6.8.2-1
sid6.9-1

Open unimportant issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2018-17983fixedvulnerablefixedfixedfixedfixedfixedcext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read du ...

Resolved issues

BugDescription
CVE-2019-3902A flaw was found in Mercurial before 4.9. It was possible to use symli ...
CVE-2018-1000132Mercurial version 4.5 and earlier contains a Incorrect Access Control ...
CVE-2018-13348The mpatch_decode function in mpatch.c in Mercurial before 4.6.1 misha ...
CVE-2018-13347mpatch.c in Mercurial before 4.6.1 mishandles integer addition and sub ...
CVE-2018-13346The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorr ...
CVE-2017-1000116Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ...
CVE-2017-1000115Mercurial prior to version 4.3 is vulnerable to a missing symlink chec ...
CVE-2017-17458In Mercurial before 4.4.1, it is possible that a specially malformed r ...
CVE-2017-9462In Mercurial before 4.1.3, "hg serve --stdio" allows remote authentica ...
CVE-2016-3630The binary delta decoder in Mercurial before 3.7.3 allows remote attac ...
CVE-2016-3105The convert extension in Mercurial before 3.8 might allow context-depe ...
CVE-2016-3069Mercurial before 3.7.3 allows remote attackers to execute arbitrary co ...
CVE-2016-3068Mercurial before 3.7.3 allows remote attackers to execute arbitrary co ...
CVE-2014-9462The _validaterepo function in sshpeer in Mercurial before 3.2.4 allows ...
CVE-2014-9390Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x befo ...
CVE-2010-4237Mercurial before 1.6.4 fails to verify the Common Name field of SSL ce ...
CVE-2008-4297Mercurial before 1.0.2 does not enforce the allowpull permission setti ...
CVE-2008-2942Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allow ...

Security announcements

DSA / DLADescription
DLA-2293-1mercurial - security update
DLA-1764-1mercurial - security update
DLA-1414-2mercurial - regression update
DLA-1414-1mercurial - security update
DLA-1331-1mercurial - security update
DLA-1224-1mercurial - security update
DSA-3963-1mercurial - security update
DLA-1072-1mercurial - security update
DLA-1005-1mercurial - security update
DLA-459-1mercurial - security update
DSA-3570-1mercurial - security update
DSA-3542-1mercurial - security update
DLA-237-1mercurial - security update
DSA-3257-1mercurial - security update

Search for package or bug name: Reporting problems