Bugzilla – Bug 1053344
VUL-0: CVE-2017-1000115: mercurial: path traversal via symlink
Last modified: 2017-10-25 16:59:27 UTC
rh#1480330 The symlink auditor is sometimes cached too long, and can be confused into allowing write access to outside the repo. https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.282017-08-10.29
Please include into current submissions.
4.2.3 was submitted to TW and Leap 42.3, which should include this fix as well.
The fix for Leap 42.2:Update was submitted via SR#516580. The fix for SLE12:Update was submitted via SR#137790. The fix for SLE11-SP3:Update was submitted via SR#137791.
This is an autogenerated message for OBS integration: This bug (1053344) was mentioned in https://build.opensuse.org/request/show/516580 42.2 / mercurial
openSUSE-SU-2017:2187-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1052696,1053344 CVE References: CVE-2017-1000115,CVE-2017-1000116 Sources used: openSUSE Leap 42.3 (src): mercurial-4.2.3-4.1 openSUSE Leap 42.2 (src): mercurial-3.8.3-2.8.1
SUSE-SU-2017:2250-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1052696,1053344 CVE References: CVE-2017-1000115,CVE-2017-1000116 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): mercurial-2.3.2-0.18.3.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): mercurial-2.3.2-0.18.3.1
SUSE-SU-2017:2251-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1052696,1053344 CVE References: CVE-2017-1000115,CVE-2017-1000116 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP3 (src): mercurial-2.8.2-15.3.1 SUSE Linux Enterprise Software Development Kit 12-SP2 (src): mercurial-2.8.2-15.3.1
released