diff options
| author | Zhixiong Chi <zhixiong.chi@windriver.com> | 2017-06-15 14:05:02 +0800 |
|---|---|---|
| committer | Armin Kuster <akuster808@gmail.com> | 2017-07-17 11:17:47 -0700 |
| commit | ef316309bbf23b503246dd735bfa2fb17e28ed44 (patch) | |
| tree | 86257819e7ebac7b87ac60120d2fa887330f5b48 /meta-oe/recipes-bsp | |
| parent | 7bd1b2a48a4ae938bd8a91d49722f9a8c2cdaf71 (diff) | |
| download | meta-openembedded-ef316309bbf23b503246dd735bfa2fb17e28ed44.tar.gz | |
mercurial: CVE-2017-9462
Backport the CVE patch from
https://www.mercurial-scm.org/repo/hg/rev/77eaf9539499
"hg serve --stdio" allows remote authenticated users to launch the
Python debugger, and consequently execute arbitrary code, by using
--debugger as a repository name.
CVE: CVE-2017-9462
Signed-off-by: Zhixiong Chi <zhixiong.chi@windriver.com>
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Diffstat (limited to 'meta-oe/recipes-bsp')
0 files changed, 0 insertions, 0 deletions
