oss-sec mailing list archives

Re: CVE Request (mercurial)


From: Ludwig Nussel <ludwig.nussel () suse de>
Date: Mon, 29 Sep 2008 16:13:56 +0200

Josh Bressers wrote:
Looks like there's one more flaw in Mercurial we missed:
http://www.selenic.com/mercurial/wiki/index.cgi/WhatsNew#head-905b8adb3420a77d92617e06590055bd8952e02b

* hgweb: fix "allowpull" permission being ignored when pulling from hgweb

Did anyone assign a CVE number for this issue yet?

cu
Ludwig

-- 
 (o_   Ludwig Nussel
 //\   
 V_/_  http://www.suse.de/
SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg)


Current thread: