Re: Security update needed for mercurial (upload error: doesn't follow naming convention)

2016-04-20 Thread Warren Young
On Apr 20, 2016, at 10:56 AM, Jari Aalto wrote: > >> 3.7.3 as a security release, with fixes for: >> >> CVE-2016-3630 Mercurial: remote code execution in binary delta decoding >> CVE-2016-3068 Mercurial: arbitrary code execution with Git subrepos >> CVE-2016-3069 Mercurial: arbitrary code execut

Re: Security update needed for mercurial (upload error: doesn't follow naming convention)

2016-04-20 Thread Jon Turney
On 20/04/2016 17:56, Jari Aalto wrote: 3.7.3 as a security release, with fixes for: CVE-2016-3630 Mercurial: remote code execution in binary delta decoding CVE-2016-3068 Mercurial: arbitrary code execution with Git subrepos CVE-2016-3069 Mercurial: arbitrary code execution when converting Git re

Re: Security update needed for mercurial (upload error: doesn't follow naming convention)

2016-04-20 Thread Corinna Vinschen
On Apr 20 19:56, Jari Aalto wrote: > > 3.7.3 as a security release, with fixes for: > > > > CVE-2016-3630 Mercurial: remote code execution in binary delta decoding > > CVE-2016-3068 Mercurial: arbitrary code execution with Git subrepos > > CVE-2016-3069 Mercurial: arbitrary code execution when conv

Re: Security update needed for mercurial (upload error: doesn't follow naming convention)

2016-04-20 Thread Jari Aalto
> 3.7.3 as a security release, with fixes for: > > CVE-2016-3630 Mercurial: remote code execution in binary delta decoding > CVE-2016-3068 Mercurial: arbitrary code execution with Git subrepos > CVE-2016-3069 Mercurial: arbitrary code execution when converting Git repos New release uploaded, but I

Re: Security update needed for mercurial

2016-04-20 Thread Corinna Vinschen
On Apr 19 17:30, Andy Moreton wrote: > On Sat 02 Apr 2016, Andy Moreton wrote: > > > Hi, > > > > The current package is for mercurial 3.5.1, but upstream have released Actually the Cygwin mercurial package is at 3.6.3. > > 3.7.3 as a security release, with fixes for: > > > > CVE-2016-3630 Mercur

Re: Security update needed for mercurial

2016-04-19 Thread Andy Moreton
On Sat 02 Apr 2016, Andy Moreton wrote: > Hi, > > The current package is for mercurial 3.5.1, but upstream have released > 3.7.3 as a security release, with fixes for: > > CVE-2016-3630 Mercurial: remote code execution in binary delta decoding > CVE-2016-3068 Mercurial: arbitrary code execution wi