1580716608
hg-git 0.8.9 has just been tagged and uploaded to PyPI. This release is compatible with the just-released Mercurial 4.3. This release includes a fix for CVE-2017-1000116. From the Mercurial release announcement: Mercurial was not sanitizing hostnames passed to ssh, allowing shell injection attacks by specifying a hostname starting with -oProxyCommand. This is also present in Git (CVE-2017-1000117) and Subversion (CVE-2017-9800), so please patch those tools as well if you have them installed. All three tools are doing their security release today.
6 lines
402 B
Text
6 lines
402 B
Text
$NetBSD: distinfo,v 1.5 2017/09/03 14:16:43 wiz Exp $
|
|
|
|
SHA1 (hg-git/0.8.9.tar.bz2) = 24e16efb49ad1617e96261144c91f937cc635e01
|
|
RMD160 (hg-git/0.8.9.tar.bz2) = 8c97efd441e84545b5aa31de3654efd2795e6286
|
|
SHA512 (hg-git/0.8.9.tar.bz2) = 3f5ec2893a0af90f8670f31c781d93d06c55d1f9f7218c9311a2647b782064d0310210f6ea59a94e7180987cd8588660bd3ab3dd85744550f16428af1cf623cc
|
|
Size (hg-git/0.8.9.tar.bz2) = 95019 bytes
|