FYI, mercurial is in universe and is therefore community maintained. I took a look at it and have prepared packages in https://launchpad.net /~ubuntu-security-proposed/+archive/ubuntu/ppa/+packages. If someone could test them and verify they are ok, I can push them out as a security update.
** Changed in: mercurial (Ubuntu) Status: Confirmed => In Progress ** Also affects: git (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: mercurial (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: git (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: mercurial (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: git (Ubuntu Vivid) Importance: High Status: Confirmed ** Also affects: mercurial (Ubuntu Vivid) Importance: High Status: In Progress ** Also affects: git (Ubuntu Utopic) Importance: Undecided Status: New ** Also affects: mercurial (Ubuntu Utopic) Importance: Undecided Status: New ** Changed in: mercurial (Ubuntu Precise) Status: New => In Progress ** Changed in: mercurial (Ubuntu Precise) Importance: Undecided => Medium ** Changed in: mercurial (Ubuntu Precise) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Changed in: mercurial (Ubuntu Trusty) Status: New => In Progress ** Changed in: mercurial (Ubuntu Trusty) Importance: Undecided => Medium ** Changed in: mercurial (Ubuntu Trusty) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Changed in: mercurial (Ubuntu Utopic) Status: New => In Progress ** Changed in: mercurial (Ubuntu Utopic) Importance: Undecided => Medium ** Changed in: mercurial (Ubuntu Utopic) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Changed in: mercurial (Ubuntu Vivid) Importance: High => Medium ** Changed in: mercurial (Ubuntu Vivid) Assignee: (unassigned) => Jamie Strandboge (jdstrand) ** Changed in: git (Ubuntu Precise) Status: New => In Progress ** Changed in: git (Ubuntu Precise) Importance: Undecided => Medium ** Changed in: git (Ubuntu Precise) Assignee: (unassigned) => Tyler Hicks (tyhicks) ** Changed in: git (Ubuntu Trusty) Status: New => In Progress ** Changed in: git (Ubuntu Trusty) Importance: Undecided => Medium ** Changed in: git (Ubuntu Trusty) Assignee: (unassigned) => Tyler Hicks (tyhicks) ** Changed in: git (Ubuntu Utopic) Status: New => In Progress ** Changed in: git (Ubuntu Utopic) Importance: Undecided => Medium ** Changed in: git (Ubuntu Utopic) Assignee: (unassigned) => Tyler Hicks (tyhicks) ** Changed in: git (Ubuntu Vivid) Status: Confirmed => In Progress ** Changed in: git (Ubuntu Vivid) Importance: High => Medium ** Changed in: git (Ubuntu Vivid) Assignee: (unassigned) => Tyler Hicks (tyhicks) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1404035 Title: Errors in handling case-sensitive directories allow for remote code execution on pull To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/git/+bug/1404035/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs