Opened 6 years ago

Closed 6 years ago

#9974 closed enhancement (fixed)

mercurial-4.4.1

Reported by: bdubbs@… Owned by: Pierre Labastie
Priority: normal Milestone: 8.2
Component: BOOK Version: SVN
Severity: normal Keywords:
Cc:

Description

New minor version.

Change History (4)

comment:1 by Pierre Labastie, 6 years ago

Owner: changed from blfs-book@… to Pierre Labastie
Status: newassigned

comment:3 by Pierre Labastie, 6 years ago

Summary: mercurial-4.4mercurial-4.4.1

Now 4.4.1

Mercurial 4.4.1 (2017-11-07)

1.1. Notable changes

Git and Subversion subrepos have been disabled by default to mitigate a
potential security risk if files overlapping with a subrepo managed to be
committed to a repository.
Subrepos are now more paranoid about symlink traversal.
The share extension handles drive letters on Windows better.
It is possible that a specially malformed repository can cause Git
subrepositories to run arbitrary code in the form of a
.git/hooks/post-update script checked in to the repository in Mercurial 4.4
and earlier. Typical use of Mercurial prevents construction of such repositories,
but they can be created programmatically.

comment:4 by Pierre Labastie, 6 years ago

Resolution: fixed
Status: assignedclosed

Fixed at r19454

Note: See TracTickets for help on using tickets.