Bug#783237: CVE-2014-9462

2015-05-06 Thread Javi Merino
Hi Alessandro, On Sat, May 02, 2015 at 09:04:42AM +0100, Javi Merino wrote: On Fri, May 01, 2015 at 08:53:28PM +0200, Alessandro Ghedini wrote: On Fri, May 01, 2015 at 07:16:07PM +0100, Javi Merino wrote: On Fri, Apr 24, 2015 at 01:21:56PM +0200, Moritz Muehlenhoff wrote: Package:

Bug#783237: CVE-2014-9462

2015-05-06 Thread Sébastien Delafond
On May/06, Javi Merino wrote: I've prepared an upload for wheezy-security, find the diff below. Can I upload it to security-master? It looks fine to me. This one will need -sa as well. Cheers, --Seb -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of

Bug#783237: CVE-2014-9462

2015-05-02 Thread Javi Merino
On Fri, May 01, 2015 at 08:53:28PM +0200, Alessandro Ghedini wrote: On Fri, May 01, 2015 at 07:16:07PM +0100, Javi Merino wrote: On Fri, Apr 24, 2015 at 01:21:56PM +0200, Moritz Muehlenhoff wrote: Package: mercurial Severity: important Tags: security Please see

Bug#783237: CVE-2014-9462

2015-05-01 Thread Alessandro Ghedini
On Fri, May 01, 2015 at 07:16:07PM +0100, Javi Merino wrote: On Fri, Apr 24, 2015 at 01:21:56PM +0200, Moritz Muehlenhoff wrote: Package: mercurial Severity: important Tags: security Please see

Bug#783237: CVE-2014-9462

2015-05-01 Thread Javi Merino
On Fri, Apr 24, 2015 at 01:21:56PM +0200, Moritz Muehlenhoff wrote: Package: mercurial Severity: important Tags: security Please see http://chargen.matasano.com/chargen/2015/3/17/this-new-vulnerability-mercurial-command-injection-cve-2014-9462.html Fix:

Bug#783237: CVE-2014-9462

2015-04-24 Thread Moritz Muehlenhoff
Package: mercurial Severity: important Tags: security Please see http://chargen.matasano.com/chargen/2015/3/17/this-new-vulnerability-mercurial-command-injection-cve-2014-9462.html Fix: http://selenic.com/hg/rev/e3f30068d2eb Cheers, Moritz -- To UNSUBSCRIBE, email to