[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 17 Sep 2008 20:38:23 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security <oss-security@...ts.openwall.com>
Cc: coley@...re.org
Subject: CVE Request (mercurial)
Hi Steve,
Looks like there's one more flaw in Mercurial we missed:
http://www.selenic.com/mercurial/wiki/index.cgi/WhatsNew#head-905b8adb3420a77d92617e06590055bd8952e02b
* hgweb: fix "allowpull" permission being ignored when pulling from hgweb
I admit I don't completely understand it. rPath seems to have a little more info:
https://issues.rpath.com/browse/RPL-2753
Thanks
--
JB
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ