mercurial (6.3.2-1+deb12u1) bookworm-security; urgency=high
authorJulien Cristau <jcristau@debian.org>
Thu, 20 Mar 2025 12:56:44 +0000 (13:56 +0100)
committerJulien Cristau <jcristau@debian.org>
Thu, 20 Mar 2025 12:56:44 +0000 (13:56 +0100)
commit1f34df4cb4714888b44dec46a4a9e95e2270f095
tree7e9699c6a1d3babf7bf96feffd0387e1527e7e9d
parent57ab725847d1100b33b83f759cde6c4b8a1b40b7
parent0774d02505f9757d3c8cdb68996e798952da38cc
mercurial (6.3.2-1+deb12u1) bookworm-security; urgency=high

  * CVE-2025-2361: reflected XSS in hgweb (closes: #1100899)
  * patchbomb: don't test ambiguous address (fixes FTBFS after python's
    fix for CVE-2023-27043).

[dgit import unpatched mercurial 6.3.2-1+deb12u1]
44 files changed:
debian/NEWS
debian/README.Debian
debian/README.source
debian/cacerts.rc
debian/changelog
debian/control
debian/copyright
debian/gbp.conf
debian/hgext.rc
debian/hgext.rc.md5sums
debian/hgrc
debian/mercurial-common.bash-completion
debian/mercurial-common.dirs
debian/mercurial-common.examples
debian/mercurial-common.install
debian/mercurial-common.maintscript
debian/mercurial-common.postinst
debian/mercurial.dirs
debian/mercurial.install
debian/mercurial.links
debian/mercurial.postinst
debian/mercurial.postrm
debian/mercurial.test_blacklist
debian/patches/0005-Tolerate-SIGINT-getting-the-kill-in-test-stdio.py.patch
debian/patches/CVE-2025-2361.patch
debian/patches/cgitb.patch
debian/patches/deb_specific__disable_libdir_replacement.patch
debian/patches/deb_specific__hgk.py.patch
debian/patches/deb_specific__optional-dependencies
debian/patches/from_upstream_stable.patch
debian/patches/openssl_3_cipher_tlsv1.patch
debian/patches/patchbomb-ambiguous-address.patch
debian/patches/proposed_upstream__doctest.path
debian/patches/py310/9_tests__silence_asyncore_smtpd_deprecation_warnings.patch
debian/patches/series
debian/patches/test-hghave-testrepo.patch
debian/rules
debian/source/format
debian/tests/control
debian/tests/hgsubversion
debian/tests/mercurial-git
debian/tests/testsuite
debian/upstream/signing-key.asc
debian/watch