mercurial (5.6.1-4+deb11u1) bullseye-security; urgency=medium
authorAndreas Henriksson <andreas@fatal.se>
Thu, 27 Mar 2025 18:23:02 +0000 (19:23 +0100)
committerAndreas Henriksson <andreas@fatal.se>
Thu, 27 Mar 2025 18:23:02 +0000 (19:23 +0100)
commit83273cc1e86ef5f68c81f4f5d1165be1718e7abf
tree0ec0554a44f1b9e23b9a3e76d34c208560c571cb
parentd2a76f041ad71c480e191d3905f1189e5cbee268
parent95b60ec6597ec84358bb5fbbb97e7d8f76cee85d
mercurial (5.6.1-4+deb11u1) bullseye-security; urgency=medium

  * Non-maintainer upload by the Debian LTS Security Team.

  [ Andreas Henriksson ]
  * Cherry-pick and massage bookworm (stable) patches by jcristau to apply
    on bullseye version of the package.

  [ Julien Cristau ]
  * CVE-2025-2361: reflected XSS in hgweb (closes: #1100899)
  * patchbomb: don't test ambiguous address
    (fixes FTBFS after python's fix for CVE-2023-27043).

[dgit import unpatched mercurial 5.6.1-4+deb11u1]
43 files changed:
debian/NEWS
debian/README.Debian
debian/README.source
debian/cacerts.rc
debian/changelog
debian/control
debian/copyright
debian/gbp.conf
debian/hg-ssh.8
debian/hgext.rc
debian/hgext.rc.md5sums
debian/hgrc
debian/mercurial-common.bash-completion
debian/mercurial-common.dirs
debian/mercurial-common.examples
debian/mercurial-common.install
debian/mercurial-common.maintscript
debian/mercurial-common.manpages
debian/mercurial-common.postinst
debian/mercurial.dirs
debian/mercurial.install
debian/mercurial.links
debian/mercurial.postinst
debian/mercurial.postrm
debian/mercurial.test_blacklist
debian/patches/0005-Tolerate-SIGINT-getting-the-kill-in-test-stdio.py.patch
debian/patches/CVE-2025-2361.patch
debian/patches/deb_specific__disable_libdir_replacement.patch
debian/patches/deb_specific__hgk.py.patch
debian/patches/deb_specific__optional-dependencies
debian/patches/from_upstream-test-subrepo-new-git.patch
debian/patches/patchbomb-ambiguous-address.patch
debian/patches/proposed_upstream__doctest.path
debian/patches/python-3.9.2.patch
debian/patches/series
debian/rules
debian/source/format
debian/tests/control
debian/tests/hgsubversion
debian/tests/mercurial-git
debian/tests/testsuite
debian/upstream/signing-key.asc
debian/watch