Overview

Request 384126 accepted

- Fix VUL-0: arbitrary code execution when converting Git repos
(CVE-2016-3069, bsc#973176):
hg-convert_fix_git_convert_using_servers_branches.name
hg-CVE-2016-3069-01-convert_add_new_non_clowny_interface.patch
hg-CVE-2016-3069-02-convert_rewrite_calls_to_Git.patch
hg-CVE-2016-3069-03-convert_dead_code_removal.patch
hg-CVE-2016-3069-04-convert_rewrite_gitpipe.patch
hg-CVE-2016-3069-05-convert_test_for_shell_injection.patch

- Fix VUL-0: arbitrary code execution with Git subrepos
(CVE-2016-3068, bsc#973177):
hg-CVE-2016-3068-subrepo_set_GIT_ALLOW_PROTOCOL.patch

- Fixes VUL-0: remote code execution in binary delta decoding
(CVE-2016-3630, bsc#973175):
hg-CVE-2016-3630-parsers_detect_short_records.patch
hg-CVE-2016-3630-parsers_fix_list_sizing_rounding_error.patch

Request History
Takashi Iwai's avatar

tiwai created request

- Fix VUL-0: arbitrary code execution when converting Git repos
(CVE-2016-3069, bsc#973176):
hg-convert_fix_git_convert_using_servers_branches.name
hg-CVE-2016-3069-01-convert_add_new_non_clowny_interface.patch
hg-CVE-2016-3069-02-convert_rewrite_calls_to_Git.patch
hg-CVE-2016-3069-03-convert_dead_code_removal.patch
hg-CVE-2016-3069-04-convert_rewrite_gitpipe.patch
hg-CVE-2016-3069-05-convert_test_for_shell_injection.patch

- Fix VUL-0: arbitrary code execution with Git subrepos
(CVE-2016-3068, bsc#973177):
hg-CVE-2016-3068-subrepo_set_GIT_ALLOW_PROTOCOL.patch

- Fixes VUL-0: remote code execution in binary delta decoding
(CVE-2016-3630, bsc#973175):
hg-CVE-2016-3630-parsers_detect_short_records.patch
hg-CVE-2016-3630-parsers_fix_list_sizing_rounding_error.patch


Maintenance Bot's avatar

maintbot accepted review

accepted


Maintenance Bot's avatar

maintbot approved review

accepted


Johannes Segitz's avatar

jsegitz moved maintenance target to openSUSE:Maintenance:4917


Johannes Segitz's avatar

jsegitz accepted request

ok

openSUSE Build Service is sponsored by