-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 27 Jun 2017 14:57:43 -0400 Source: mercurial Binary: mercurial-common mercurial Architecture: source all amd64 Version: 2.2.2-4+deb7u4 Distribution: wheezy-security Urgency: high Maintainer: Python Applications Packaging Team <python-apps-team@lists.alioth.debian.org> Changed-By: Antoine Beaupré <anarcat@debian.org> Description: mercurial - easy-to-use, scalable distributed version control system mercurial-common - easy-to-use, scalable distributed version control system (common Closes: 861243 Changes: mercurial (2.2.2-4+deb7u4) wheezy-security; urgency=high . * Non-maintainer upload by the LTS Security Team. * CVE-2017-9462: "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name. (Closes: #861243) Checksums-Sha1: d95481a29928553c0ab63eee6ac9c1fa4756d272 2178 mercurial_2.2.2-4+deb7u4.dsc b580e50eb7e3439b7490b1824995158e5011b4ee 53259 mercurial_2.2.2-4+deb7u4.debian.tar.gz dca1e588bffbf0226a65094bf2ea9ebfb35d389a 2320924 mercurial-common_2.2.2-4+deb7u4_all.deb 154d57c2590a9e18efbe24a25f4dfafc0f8a6db4 92960 mercurial_2.2.2-4+deb7u4_amd64.deb Checksums-Sha256: 7db66ec2657c9f1c2b63722edac2d786f26f9f582d4e56f061b513df5cd52179 2178 mercurial_2.2.2-4+deb7u4.dsc e3441baa8d665cc986310593d73d3d4d5bcc4fa93cb611ae127440f6fcc1218d 53259 mercurial_2.2.2-4+deb7u4.debian.tar.gz 23ff323780e09e93ac670de73dc6c80dfd6cef78b89c9f33815cf71afde3bd6b 2320924 mercurial-common_2.2.2-4+deb7u4_all.deb c7c4034a456c5844020137db2e275fe014d01aea3e5696cc2c3bc36fe90628c7 92960 mercurial_2.2.2-4+deb7u4_amd64.deb Files: 756b274039851c6249e3208c88c4dd79 2178 vcs optional mercurial_2.2.2-4+deb7u4.dsc 571aa05cd4068e4f8c535f1a2d1ca24c 53259 vcs optional mercurial_2.2.2-4+deb7u4.debian.tar.gz feff9c479099f5a0bb2287889ea71418 2320924 vcs optional mercurial-common_2.2.2-4+deb7u4_all.deb 952c2dbeeaa7f6d2ad3ce4159a1be8ac 92960 vcs optional mercurial_2.2.2-4+deb7u4_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEjckBzmQUbASK1Q+7eSFSUnt1kh4FAllVTP0ACgkQeSFSUnt1 kh4sExAAj88jTUvm5/8Qsbn3og7KsXEZAosPnubSAwF9K75ORTMop3oQKluEL3SN k3lxx3u96if5oPCidJqXVZdiUWoWJCJ22tMJoSCGItZxEQJqck4PGlV4jtsaeRwZ MnWTqSqGUMSRBFbntFyy8+FE5snaAKipB291t9nDHSC32p9nqMCAFoRdIXmQ5ZsH 4bEeJHxpgdp98Ihg334CXw6FxvN8cYGg0eC0egVUeNVOpDsRB14qzqkLH5pDSazX xeIoQymBRz3IBYNZ4tru5/oaHWLy4aVYhZ3evoJ3SZi/FdRzAENrhoiH2mEtANtQ b+FlUPnEkE9uovXL8de8XrEowfGXGsXnD6T6ld0raDkpUj+o684A+UcL/a8ONyo3 FxWJZIQEvkOdlDZs+6HSyz2J9aEdX/Pe3q6JThs3M9YOm8eSHak3o2YkMSl6Y1e9 uu20a/usUSDJCOXv4UQWtStv9/qIvx1cbbopUtEabLO9iRGvTNUqcGwq3qhH2ctC kI+F3pJXE/gPJPvv+em7RwcdVCXrt6ZYM3QXPPB6eAruM5XM/Qgk1LFQFpzn7HA8 KrWGwR+WgcDekZ/KP1eOeTb15nSj3NMSD7c47ecKXAiVaEif7Brlm2GI+1VYjfSl H5bTM9tqCg/oCjRjXvURy7gIPes0QEEAQUACk6uE0TyGG59uLV8= =PIny -----END PGP SIGNATURE-----