Candidate: CVE-2008-4297 PublicDate: 2008-09-27 10:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4297 Description: Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request. Ubuntu-Description: Notes: kees> only part of the examples Bugs: Priority: negligible Discovered-by: Assigned-to: CVSS: Patches_mercurial: upstream_mercurial: released (1.0.2) dapper_mercurial: ignored feisty_mercurial: ignored gutsy_mercurial: ignored hardy_mercurial: ignored devel_mercurial: not-affected